AWS organizations: Add account migration prerequisites and root user access prep
Summary
Added notes that Seller of Record must match, that creating an organization moves the account to a paid plan, and a new optional step to prepare root user access (including removing root MFA) before ownership changes.
Security assessment
The change documents root user access and MFA handling during account ownership migration, which is security-adjacent identity guidance, but it is procedural documentation rather than a fix for a specific vulnerability.
Evidence
+ * If the account has multi-factor authentication (MFA) registered for the root user, remove it before the migration. Otherwise, the new owner might not be able to sign in as the root user.
Diff
diff --git a/organizations/latest/userguide/orgs_account_migration.md b/organizations/latest/userguide/orgs_account_migration.md index f69b2ddf5..f5a5e9eff 100644 --- a//organizations/latest/userguide/orgs_account_migration.md +++ b//organizations/latest/userguide/orgs_account_migration.md @@ -28,0 +29,8 @@ To migrate an account to a new organization, you must wait until at least seven +**Seller of Record must match** + +The Seller of Record (SOR) of the account you are moving must match the Seller of Record of the destination organization. If the accounts have different Sellers of Record, the move fails. + +**Creating an organization moves the account to a paid plan** + +Creating an organization moves the AWS account from the Free Tier to a paid plan. + @@ -126,0 +135,11 @@ If you are migrating an account to or from an organization managed by AWS Contro +### (Optional) Step 6: Prepare root user access for the new owner + +If ownership of the account is changing as part of the migration, prepare root user access for the new owner before you migrate the account. + + * If the account has multi-factor authentication (MFA) registered for the root user, remove it before the migration. Otherwise, the new owner might not be able to sign in as the root user. + + * To change the root user email address to the new owner's email address after the migration, make sure that the destination organization uses all features. If the destination organization does not use all features, change the root user email address before you migrate the account. + + + +