Provision Account Factory accounts with AWS Service Catalog - AWS Control Tower

Provision Account Factory accounts with AWS Service Catalog

The following procedure describes how to create and provision accounts as an IAM Identity Center end user, through AWS Service Catalog. This procedure also is referred to as advanced account provisioning, or manual account provisioning. Optionally, you may be able to provision accounts programmatically, with the AWS CLI or with AWS Control Tower Account Factory for Terraform (AFT).

To provision accounts individually in Account Factory, as an end user

  1. Sign in from your user portal URL.

  2. From Your applications, choose AWS Account.

  3. From the list of accounts, choose the account ID for your management account. This ID may also have a label, for example, (Management).

  4. From AWSServiceCatalogEndUserAccess, choose Management console. This opens the AWS Management Console for this user in this account.

  5. Ensure that you've selected the correct AWS Region for provisioning accounts, which should be your AWS Control Tower home region.

  6. Search for and choose Service Catalog to open the AWS Service Catalog console.

  7. From the navigation pane, choose Products.

  8. Select AWS Control Tower Account Factory, then choose the Launch product button. This selection starts the wizard to provision a new account.

  9. Fill in the information, and keep the following in mind:

    • The SSOUserEmail can be a new email address, or the email address associated with an existing IAM Identity Center user. Whichever you choose, this user will have administrative access to the account you're provisioning.

    • The AccountEmail must be an email address that isn't already associated with an AWS account. If you used a new email address in SSOUserEmail, you can use that email address here.

  10. Do not define TagOptions and do not enable Notifications, otherwise the account can fail to be provisioned. When you're finished, choose Launch product.

  11. Review your account settings, and then choose Launch. Do not create a resource plan, otherwise the account will fail to be provisioned.

  12. Your account is now being provisioned. It can take a few minutes to complete. You can refresh the page to update the displayed status information.


    Only one account can be provisioned at a time.