Hi All, I am new to AWS and my organisation has decided to move billing to an AWS Partner so that we get due date extension and I am in charge of the transition.
As part of the process, we should accept a AWS Organisation invite from the partner account. The invitation message reads
> The organization with the following details invites your AWS account to become a member of the organization. This organization has all features enabled and can assume full control of your account.
From reading the docs I understood the following
• Even after accepting the invite I have to manually create OrganizationAccountAccessRole for the partner management account and only then they can manage our account.
What I don’t understand clearly from the document are the following
- What access does the management account have if I only accept the invite and don’t create the OrganizationAccountAccessRole. What they can see and can’t see.
- Does SCP (Service Control Policies) need OrganizationAccountAccessRole to work? I read that SCP automatically applies on member accounts so accepting the invite will in anyway modify our account without OrganizationAccountAccessRole?