Skip to content

/AWS1/CL_FMS=>PUTADMINACCOUNT()

About PutAdminAccount

Creates or updates an Firewall Manager administrator account. The account must be a member of the organization that was onboarded to Firewall Manager by AssociateAdminAccount. Only the organization's management account can create an Firewall Manager administrator account. When you create an Firewall Manager administrator account, the service checks to see if the account is already a delegated administrator within Organizations. If the account isn't a delegated administrator, Firewall Manager calls Organizations to delegate the account within Organizations. For more information about administrator accounts within Organizations, see Managing the Amazon Web Services Accounts in Your Organization.

Method Signature

IMPORTING

Required arguments:

IV_ADMINACCOUNT TYPE /AWS1/FMSAWSACCOUNTID /AWS1/FMSAWSACCOUNTID

The Amazon Web Services account ID to add as an Firewall Manager administrator account. The account must be a member of the organization that was onboarded to Firewall Manager by AssociateAdminAccount. For more information about Organizations, see Managing the Amazon Web Services Accounts in Your Organization.

Optional arguments:

IO_ADMINSCOPE TYPE REF TO /AWS1/CL_FMSADMINSCOPE /AWS1/CL_FMSADMINSCOPE

Configures the resources that the specified Firewall Manager administrator can manage. As a best practice, set the administrative scope according to the principles of least privilege. Only grant the administrator the specific resources or permissions that they need to perform the duties of their role.