Enrolling an Account
If you created an account via Organizations or invited an account to your organization before setting up a landing zone via RGC, the account will not be automatically enrolled in the landing zone, and you need to manually enroll the account so that it will be governed in the landing zone.
Constraints
- If an account has enabled Config and has a resource recorder, exercise caution when enrolling the account because the recorder configurations will be overwritten after enrollment.
- If you want to transfer an account from one landing zone to another one by performing an account enrollment, unmanage the account from the original landing zone and then enroll it in the new landing zone. If you have enrolled the account in the new landing zone, manually delete the resources, such as agencies and policies, of the account from the original landing zone, or an error will occur.
- Before enrolling an invited account, make sure you have met the requirements in Prerequisites. Otherwise, the account enrollment may fail.
Prerequisites
Perform the following steps only when you want to enroll accounts you invited into your organization. When enrolling accounts you created in the organization, skip the steps.
- Log in to Huawei Cloud using the account you want to enroll, and navigate to the IAM console.
- In the navigation pane, choose Agencies and click Create Agency in the upper right corner.
    
    Figure 1 Creating an agency  
- Set the agency name to OrganizationAccountAccessAgency.
    
    Figure 2 Specifying an agency name  
- Set Agency Type to Account and Delegated Account to the RGC management account name.
- Configure a validity period and enter a description for the agency.
- Click OK.
- In the displayed dialog box, click Authorize.
- Select Security Administrator, FullAccess, and Tenant Guest.
    
    Figure 3 Permissions to be granted to the agency 
- Click Next to set the authentication scope.
- Click OK. The agency is created. You can then follow the instructions in Procedure to enroll the account.
    
      Once the OrganizationAccountAccessAgency agency is created, it cannot be deleted; otherwise, RGC services will become unavailable. 
Procedure
- Log in to Huawei Cloud using the management account, and navigate to the RGC console.
- Access the Organization page, locate the account you want to enroll, and click Enroll in the Operation column.
    
    Figure 4 Enrolling an account  
- Select a registered OU where your account will be added, and enable all governance policies configured for the OU for the account.
    
    Figure 5 Selecting a registered OU  
- (Optional) Configure an RFS template in the account factory. Select an RFS template and its version. If you select an RFS, you can copy and create accounts in batches.
    
    For more information about RFS templates, see Templates.- Select Template: Select a template you created in RFS.
- Template Version: Select the version for the template.
- Configuration Parameters: Modify parameter settings in the template based on service requirements.
       Figure 6 Configuring a template  
 
- Click Enroll Account. You can view the enrollment status in the organizational structure. Once enrolled, the account will be governed in the landing zone.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot 
    