I'm getting an error to enroll account into control tower, though my colleague is able to enroll new account with the same permission.
Error Details:- An unknown error occurred. Try again later, or contact AWS Support. No launch paths found for resource: prod-xxxxxxxxxxxx
AWS Control Tower can't create your account due to potential drift in your landing zone. Check your landing zone and try using the advanced account provisioning method to create your account.
Note: There is no Drift in our landing zone
I tried all the possible solution but still the same error exists. Does anyone face the same issue?
I got this error when I want to enroll an account on Account Account factory on Control Tower
Then I find this document and repair Landing zone from landing zone settings works for me:
https://docs.aws.amazon.com/controltower/latest/userguide/drift.html
Update: I have this error today with similar issues when I want to create account
I figure out because I login as an IAM identity user (SSO login), and on
Service Catalog
console,Administration
---->Portfolio
---->Access
sections, you need togrand access
to your Portfolio.