Accepting and rejecting resource share
invitations
To access shared resources, the owner of the resource share must add you as a principal. The owner can add any of the following as a principal to the resource share.
-
The organization of which your account is a member
-
An organizational unit (OU) that contains your account
-
Your individual account
-
For supported resource types, your specific IAM role or user
If you're added to the resource share through an AWS account that is a member of an organization in AWS Organizations, and sharing within the organization is enabled, then you automatically get access to the shared resources without having to accept an invitation. Service principals also get automatic access to shared resources without accepting an invitation. If the account through which you receive access is later removed from the organization, then any principals in that account automatically lose access to the resources that were accessed through that resource share.
If you're added to a resource share by one of the following, you receive an invitation to join the resource share:
-
An account outside of your organization in AWS Organizations
-
An account inside your organization when sharing with AWS Organizations is not enabled
If you receive an invitation to join a resource share, you must accept it to access its shared resources. If you decline the invitation, you can't access the shared resources.
For the following resource types you have seven days to accept the invitation to join the share for the following resource types. If you don't accept the invitation before it expires, the invitation is automatically declined.
Important
For shared resource types not on the following list, you have 12 hours to accept the invitation to join the resource share. After 12 hours, the invitation expires and the end user principal in the resource share is disassociated. The invitation can no longer be accepted by end users.
-
Amazon Aurora – DB clusters
-
Amazon EC2 – capacity reservations and dedicated hosts
-
AWS License Manager – License configurations
-
AWS Outposts – Local gateway route tables, outposts, and sites
-
Amazon Route 53 – Forwarding rules
-
Amazon VPC – Customer-owned IPv4 addresses, prefix lists, subnets, traffic mirror targets, transit gateways, transit gateway multicast domains
To respond to an invitation to a resource share
-
Navigate to the Shared with me : Resource shares
page in the AWS RAM console. -
Because AWS RAM resource shares exist in specific AWS Regions, choose the appropriate AWS Region from the dropdown list in the upper-right corner of the console. To see resource shares that contain global resources, you must set the AWS Region to US East (N. Virginia), (
us-east-1
). For more information about sharing global resources, see Sharing Regional resources compared to global resources. -
Review the list of resource shares to which you have been added.
The Status column indicates your current participation status for the resource share. The
Pending
status indicates that you have been added to a resource share, but you have not yet accepted or rejected the invitation. -
To respond to the resource share invitation, select the resource share ID and choose Accept resource share to accept the invitation, or Reject resource share to decline the invitation. If you reject the invitation, you don't get access to the resources. If you accept the invitation, you gain access to the resources.