AWS Control Tower Account Factory for Terraform now re-applies customizations when accounts move between OUs
News
AWS Control Tower Account Factory for Terraform (AFT) now automatically re-applies account customizations when accounts move to different Organizational Units, eliminating manual re-application and configuration drift risks.
- Enable automatic re-application by setting aft_customization_triggers = ["account_move"] in AFT configuration
- Re-application workflow skips bootstrap and provisioning phases for faster execution
- Individual accounts can be excluded using account_skip_customization_triggers = "true"
- Additional improvements include custom Terraform Cloud workspace naming and tighter logging bucket access controls
- Improved scaling for large-scale AWS Enterprise Support enrollment
This capability helps organizations maintain compliance and security baselines tied to OU membership with reduced operational overhead.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Dec 10
2024
2024
AWS Account vending by integrating ServiceNow with AWS Control Tower Account Factory for Terraform
Jul 10
2026
2026
AWS Organizations now applies account departure security controls by default for new organizations created via AWS Organizations console
Jul 2
2026
2026
Amazon SageMaker Unified Studio now supports Terraform for provisioning
Aug 18
2026
2026
IAM Policy Autopilot now supports Terraform plan files
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.