These is the list of tasks that need to be done via ClickOps in a new AWS Account before you can deploy org-kickstart.
- Add MFA to root
- Enable IAM access to billing (this is still a thing in 2023?)
- Go to Organizations and create an Organization
- Go to AWS SSO, and enable it
- Add yourself as a user
- Create a pre-defined Permission Set named TempAdministratorAccess. Probably want the duration as 4 hours.
- Assign the Permission Set to the new Payer/Org Management Account
- Activate trusted access with AWS Organizations to use service-managed permissions for CloudFormation stacksets (must be done via console)
Log out of root and never use it again.
- Check Email and create your IAM Identity Center account.
- Add MFA to that account
- Import Admin creds to environment
You're now ready to run org-kickstart