Enabling all features in your organization
Amazon Organizations has two available feature sets:
-
All features – This feature set is the preferred way to work with Amazon Organizations, and it includes Consolidating Billing features. When you create an organization, enabling all features is the default. With all features enabled, you can use the advanced account management features available in Amazon Organizations such as integration with supported Amazon services and organization management policies.
-
Consolidated Billing features – All organizations support this subset of features, which provides basic management tools that you can use to centrally manage the accounts in your organization.
If you create an organization with consolidated billing features only, you can later enable all features. This page describes the process of enabling all features.
Before enabling all features
Before changing from an organization that supports only consolidated billing features to an organization supporting all features, note the following:
-
When you start the process to enable all features, Amazon Organizations sends a request to every member account that you invited to join your organization. Every invited account must approve enabling all features by accepting the request. Only then can you complete the process to enable all features in your organization. If an account declines the request, you must either remove the account from your organization or resend the request. The request must be accepted before you can complete the process to enable all features. Accounts that you created using Amazon Organizations don't get a request because they don't need to approve the additional control.
-
You can continue inviting accounts to your organization while enabling all features. The owner of an invited account is informed by the invitation whether they are joining an organization with consolidated billing only, or with all features enabled.
-
If you invite an account during the process to enable all features, the invitation states that the organization they are joining has all features enabled. If you cancel the process to enable all features before the account accepts the invitation, that invitation is canceled. You must invite the account again to be a member of an organization with consolidated billing features only.
-
If you invite an account and the invitation is not yet accepted before you begin the process to enable all features, that invitation is canceled because the invitation states that the organization has consolidated billing features only. You must invite the account again to be a member of an organization with all features enabled.
-
-
You can also continue creating accounts in the organization. That process isn't affected by this change.
-
Amazon Organizations verifies that every member account has a service-linked role named
AWSServiceRoleForOrganizations
. This role is mandatory in all accounts to enable all features. If you deleted the role in an invited account, accepting the invitation to enable all features recreates the role. If you deleted the role in an account that was created using Amazon Organizations, that account receives an invitation specifically to recreate that role. All of these invitations must be accepted for the organization to complete the process of enabling all features. -
The migration from consolidated billing features to all features is one-way. You can't switch an organization with all features enabled back to consolidated billing features only.
Beginning the process to enable all features
When you sign in to your organization's management account, you can begin the process to enable all features. To do this, complete the following steps.
Minimum permissions
To enable all features in your organization, you must have the following permission:
-
organizations:EnableAllFeatures
-
organizations:DescribeOrganization
– required only when using the Organizations console
Notes
-
A countdown of 90 days begins when the request is sent to the member accounts. All accounts must approve the request within that time period or the request expires. If the request expires, all requests related to this attempt are canceled, and you have to start over with step 2.
-
Once you make the request to enable all features, any existing unaccepted account invitations will be cancelled.
-
During the all features migration process, you can still initiate new account invitations and create new accounts.
After all invited accounts in the organization approve their requests, you can finalize the process and enable all features. You can also immediately finalize the process if your organization doesn't have any invited member accounts. To finalizing the process, continue with Finalizing the process to enable all features.
Approving the request to enable all features or to recreate the service-linked role
When you sign in to one of the organization's invited member accounts, you can approve
a request from the management account. If your account was originally invited to join
the organization, the invitation is to enable all features and implicitly includes
approval for recreating the AWSServiceRoleForOrganizations
role, if needed. If your account
was instead created using Amazon Organizations and you deleted the AWSServiceRoleForOrganizations
service-linked role, you receive an invitation only to recreate the role. To do this,
complete the following steps.
Important
If you enable all features, the management account in the organization can apply policy-based controls on your member account. These controls can restrict what users and even what you as the administrator can do in your account. Such restrictions might prevent your account from leaving the organization.
Minimum permissions
To approve a request to enable all features for your member account, you must have the following permissions:
-
organizations:AcceptHandshake
-
organizations:DescribeOrganization
– required only when using the Organizations console -
organizations:ListHandshakesForAccount
– required only when using the Organizations console -
iam:CreateServiceLinkedRole
– required only if theAWSServiceRoleForOrganizations
role must be recreated in the member account
Finalizing the process to enable all features
All invited member accounts must approve the request to enable all features. If there are no invited member accounts in the organization, the Enable all features progress page indicates with a green banner that you can finalize the process.
Minimum permissions
To finalize the process to enable all features for the organization, you must have the following permission:
-
organizations:AcceptHandshake
-
organizations:ListHandshakesForOrganization
-
organizations:DescribeOrganization
– required only when using the Organizations console
The next steps:
-
Enable the policy types that you want to use. After that, you can attach policies to administer the accounts in your organization. For more information, see Managing policies in Amazon Organizations.
-
Enable integration with supported services. For more information, see Using Amazon Organizations with other Amazon services.