AWS Control Tower supports automatic enrollment of accounts

Published
November 10, 2025
https://aws.amazon.com/about-aws/whats-new/2025/11/aws-control-tower-automatic-enrollment

AWS Control Tower Auto-Enrollment Feature

AWS Control Tower customers can now move their accounts to an Organizational Unit (OU) to enroll them under AWS Control Tower governance. This simplifies account creation and enrollment processes, ensuring consistency across the AWS environment.

When an account is moved to a new OU, AWS Control Tower automatically enrolls the account, applying baseline configurations and controls from the new OU and removing those from the original OU. This feature is available for customers on landing zone version 3.1 and higher.

What to do

  • Opt in to the auto-enrollment feature by toggling the flag in Landing Zone settings or using the Create or UpdateLandingZone APIs.
  • Move accounts to the desired OU using the AWS Organizations console or the CreateAccount and MoveAccount APIs.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.