awslabs / landing-zone-accelerator-on-aws

Deploy a multi-account cloud foundation to support highly-regulated workloads and complex compliance requirements.
https://aws.amazon.com/solutions/implementations/landing-zone-accelerator-on-aws/
Apache License 2.0
558 stars 447 forks source link

Managing alternate contacts #341

Open michael-kutsch opened 11 months ago

michael-kutsch commented 11 months ago

Is your feature request related to a problem? Please describe. When adding new accounts, there is a need to set alternate contacts. Currently, this either has to be done manually or a custom automation has to be implemented to do that. Also, there is currently no possibility to edit existing contact information of each member account in LZA.

As stated in the Security Maturity Model, this is one of the first things to do regarding security in a multi-account setup (especially as the LZA is designed for regulated industries).

Describe the feature you'd like Being able to create new accounts is great, and it would be very beneficial for billing, security and operations to be able to configure the alternate contacts in accounts-config.yaml besides the root account email address, so a rolled out account does not need to be edited afterwards either manually or through custom automation. Especially when an alternate contact has to be changed, it replaces tedious work and custom implementation.

Additional context It could be a low hanging fruit, as there are ready AWS solutions based on lambda out there, which could be added quite easily in the management account.

bhkhatri221 commented 11 months ago

Hello @michael-kutsch, thank you for filing a feature request with the Landing Zone Accelerator team! Our team will evaluate the applicability of this request for a future release.

We will keep this issue open for tracking purposes and keep you aware of any status updates going forward. Thank you for supporting Landing Zone Accelerator!

chakreshkyndryl commented 5 months ago

is there an update on this request, is it already added ?

aaronjones commented 3 weeks ago

I am also eager to see an update on this one. Even a "ditto" option for additional accounts to mirror the management account's additional contacts would be a good fist step. I would like to see support cases automatically CC'd to the operations contact without having to manually update each child account additional contacts in the organization.