Error: "UnknownResourceException"
Scenario
You get one of the following errors:
-
"
CannotCreateResourceShare: UnknownResourceException: OrganizationalUnit ou-
"xxxx
could not be found -
"
CannotUpdateResourceShare: UnknownResourceException: OrganizationalUnit ou-
".xxxx
could not be found
Cause
These errors can occur if you enable integration between AWS RAM and AWS Organizations by
using either the Organizations console or
the Organizations EnableAWSServiceAccess API instead of by using the AWS RAM console. When you
enable integration by using the Organizations console or API, the service doesn’t create the
AWSServiceRoleForResourceAccessManager
role in your account. That
role is needed to access information about your organization. Because the role
wasn't created, AWS RAM can’t access details about the accounts or organizational
units (OUs) in your organization.
Solution
To resolve the issue, turn off integration between AWS RAM and AWS Organizations. Then turn it on again by calling the AWS RAM EnableSharingWithAwsOrganization API operation, or by using the AWS Management Console to perform the following steps.
Important
When you disable trusted access to AWS Organizations, principals within your organization are removed from all resource shares and lose access to those shared resources.
-
Sign in to your the management account of your organization using an IAM role or user with administrative permissions.
-
Navigate to the Services page in the AWS Organizations console
. -
Choose RAM.
-
Choose Disable trusted access.
-
Navigate to the Settings page in the AWS RAM console
. -
Select the box Enable sharing with AWS Organizations, and then choose Save settings.
You should now be able to use AWS RAM to share your resources with accounts and OUs in the organization.