AWS Organizations requirements
Learn about the AWS Organizations requirements.
This topic describes how to prepare an AWS account for onboarding with SoftwareOne.
It describes how to enable AWS Organizations, required organizational services, and settings needed to support secure onboarding and governance.
Enable AWS Organizations
AWS Organizations is required to onboard Essentials and manage organization-wide services.
To enable AWS Organizations:
Sign in to the AWS Management Console.
Open AWS Organizations.
Choose Create an organization.
Select Enable all features.
All features must be enabled.
The account used to create the organization becomes the AWS Organizations management account.
After enabling all features, this setting cannot be reverted.
Enable required organizational services
The following services must be enabled at the AWS Organizations level to support secure and automated onboarding.
This is done from the organization management account and only needs to be completed once.
Enable Service Control Policies (SCPs)
SCPs allow organization-wide governance controls to be applied across AWS accounts. To enable SCPs:
Open AWS Organizations.
Select Policies.
Verify that Service control policies are enabled.
If SCPs are disabled, choose Enable.
No policies need to be created or attached at this stage.
Enable CloudTrail as an Organizational Service
Enabling CloudTrail as an organizational service allows the organization to manage organization-level CloudTrail configurations when required by services such as Landing Zones.
Enabling this setting does not create or configure any CloudTrail trails.
Open AWS Organizations.
Select Services.
Locate AWS CloudTrail.
Verify that CloudTrail is enabled for the organization.
No CloudTrail trails need to be created manually.
Enable CloudFormation StackSets
CloudFormation StackSets must be enabled both in AWS Organizations and in the CloudFormation console. Those are required to complete SoftwareOne onboarding.
Enable StackSets in AWS Organizations
Open AWS Organizations.
Select Services.
Locate AWS CloudFormation StackSets.
Verify that StackSets is enabled for the organization.
Enable StackSets in AWS CloudFormation
Open AWS CloudFormation.
Select StackSets from the navigation menu.
If prompted, enable StackSets.
Verify that service-managed permissions are available.
You do not need to create any StackSets manually.
Activate billing access for IAM users and roles
IAM users and roles cannot access AWS Billing and Cost Management by default. Billing access must be enabled to allow delegated users and roles to view billing information.
In the AWS Management Console, open Account settings or use the account menu in the upper-right corner and select Account.
Scroll to IAM user and role access to Billing information.
Select Edit.
Enable Activate IAM Access.
Choose Update.
Activating IAM access alone doesn't grant the roles the necessary permissions for these Billing and Cost Management console pages. In addition to activating IAM access, you must also attach the required IAM policies to those roles.
Next steps
After completing these requirements, return to the SoftwareOne Marketplace purchase flow and provide your AWS Organizations management account ID to continue onboarding.
Last updated
Was this helpful?