AWS Security ChangesHomeSearch

AWS organizations: Clarifies removing accounts and delegated administrator deregistration

Service: organizations · 2026-09-27 · Documentation low

File: organizations/latest/userguide/orgs_manage_accounts_remove.md

Summary

Adds notes about ConstraintViolationException when removing accounts (missing standalone-account information), Enterprise Support billing options during migration, and updates the delegated administrator guidance to require deregistering the delegated administrator (or changing it) before the account can be removed.

Security assessment

The change is procedural documentation for removing accounts from an organization, including the requirement to deregister a delegated administrator (a privileged role) first. It touches authorization hygiene around account removal but does not describe or remediate any specific vulnerability, credential, or exposure.

Evidence

If the account is a delegated administrator, you must first deregister it (or change the delegated administrator to another account that is remaining in the organization) before you can remove it.

Diff

diff --git a/organizations/latest/userguide/orgs_manage_accounts_remove.md b/organizations/latest/userguide/orgs_manage_accounts_remove.md
index 8b4c22a65..ef7e2455c 100644
--- a//organizations/latest/userguide/orgs_manage_accounts_remove.md
+++ b//organizations/latest/userguide/orgs_manage_accounts_remove.md
@@ -26,0 +27,8 @@ For each account that you want to make standalone, you must choose a support pla
+###### Note
+
+If you receive a `ConstraintViolationException` when you try to remove an account, the account is likely missing information that is required for it to operate as a standalone account, such as a valid payment method or verified contact information. Provide the missing standalone-account information described in this section, and then try the operation again.
+
+###### Note
+
+If you have AWS Enterprise Support and you are migrating accounts to another organization, you can work with Support to manage the billing during the migration. Open a billing support case from the management account to ask about options for handling charges for the standalone period, such as invoice-based billing, so that a separate payment method might not be required on each account. Availability depends on your support plan and billing configuration.
+
@@ -37 +45 @@ At the moment the account successfully leaves the organization, the owner of the
-The account that you want to remove must not be a delegated administrator account for any AWS service enabled for your organization. If the account is a delegated administrator, you must first change the delegated administrator account to another account that is remaining in the organization. For more information about how to disable or change the delegated administrator account for an AWS service, see the documentation for that service.
+The account that you want to remove must not be a delegated administrator account for any AWS service enabled for your organization. If the account is a delegated administrator, you must first deregister it (or change the delegated administrator to another account that is remaining in the organization) before you can remove it. You deregister a delegated administrator from the console or API of the AWS service that it administers; some services also support the AWS Organizations `deregister-delegated-administrator` AWS CLI command. To find the service and its delegated administrator management instructions, see [AWS services that you can use with AWS Organizations](./orgs_integrate_services_list.html).