Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Permissions required for accounts

Focus mode
Permissions required for accounts - AWS Control Tower

The permissions required for each method of provisioning and updating accounts are discussed in each section, respectively. With the appropriate user group permissions, provisioners can specify standardized baselines and network configurations for any accounts in their organization.

Note

When provisioning an account, the account requester always must have the CreateAccount and the DescribeCreateAccountStatus permissions. This permission set is part of the Admin role, and it is given automatically when a requester assumes the Admin role. If you delegate permission to provision accounts, you may need to add these permissions directly for the account requestors.

When you create accounts from the AWS Control Tower console with Account Factory, you must be signed into an account with an IAM user that has the AWSServiceCatalogEndUserFullAccess policy enabled, along with permissions to use the AWS Control Tower console, and you cannot be signed in as the Root user.

For general information about permissions required in AWS Control Tower, see Using identity-based policies (IAM policies) for AWS Control Tower. For information about roles and accounts in AWS Control Tower, see Roles and accounts.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.