Connect your linked accounts

This article describes how to integrate your linked accounts with Umbrella for us to create recommendations for each linked account. In this process, you'll assign a read-only policy to each linked account and associate it with a role.

There are few methods to connect your linked accounts:

  1. Connect All Linked Accounts - Current & Future (Recommended 💫)
    Use a Stack in your payer account that grants read-only permissions to all current and future linked accounts under your payer account. This ensures that any new linked accounts will automatically be included without requiring any action.

  2. Connect All Current Available Linked Accounts- Current
    This StackSet will propagate the necessary read-only permissions across all linked accounts under the payer account.

    Note: In case some of your linked accounts already have the needed permissions, this option is not relevant. Instead, we recommend using the third option.

  3. Connect Linked Accounts Based on Tagging
    Create a Stack in your payer account that applies read-only permissions to linked accounts based on specific tags. This way, only accounts with the defined tag will be connected to Umbrella.

  4. Connect Each Linked Account manually via the Umbrella UI
    Best suited for small accounts.
    You can manually connect each linked account from within the Umbrella interface by assigning read-only permissions for each account.


Connect All Linked Accounts (Including all future Accounts)

  1. From Umbrella's main page click on Account.

  1. Click on the Cloud Accounts tab and copy the external ID value of your account.

  1. Log into the AWS console for the payer account: https://aws.amazon.com/

  2. Navigate to CloudFormation > Stacks and click on Create Stack.


  1. For the Prepare template, select the Choose an existing template. Then, select Upload a template file, upload the following file, and click on Next.

  1. Choose a name for the Stack, enter the external ID you copied in step #2, and click on Next.

  2. Click on Next.

  3. On Umbrella, navigate to Accounts > Linked account page, and click on Validate All Connections to validate a successful connection.


  1. You will start seeing recommendations the next time your invoice runs (which occurs automatically every day).

❗ Note: From time to time, we update our Policy by adding the required permissions. The Policy is automatically updated in the Template URL, so all future linked accounts will receive the latest version.
However, for existing linked accounts, you will need to manually update the Policy.
Please follow the instructions below to update the Policy:

  • Go to AWS CloudFormation > StackSets.
  • The stack should have created a StackSet named "AnodotLinkedAccount"; click on it.
  • Under Organizational unit IDs, copy the AWS OU ID value.
  • From the top right side of the screen, click on Actions > Edit StackSet details.
  • Under Prerequisite - Prepare template, select Replace current template, then choose Amazon S3 URL
  • and paste the following link in the field (it hosts the latest version of the policy): https://pileus-cloudformation-public.s3.amazonaws.com/PileuseOnboardingCFT.json
  • Click Next.
  • In Step 4, under Organizational units (OUs), paste the OU ID you copied in Step 3.
  • Select the same region where the original stack was created.
  • Click Submit.

The StackSet may take some time to run. Once it completes, you'll see the updated policy applied across all linked accounts under the payer. Note that it can be done per linked account as well (define it in the linked account, not the payer).



Connect All Linked Accounts Under the Payer Account

  1. From Umbrella's main page click on Account.

  2. Click on the Cloud Accounts tab and copy the external ID value of your account.


  1. Log into the AWS console for the payer account: https://aws.amazon.com/

  2. Navigate to CloudFormation > StackSet and click on Create StackSet.

  3. Use the following template URL and click on Next.
    https://pileus-cloudformation-public.s3.amazonaws.com/PileuseOnboardingCFT.json

  4. Name the StackSet, enter the External ID you copied in Step 2, and Click on Next.

  5. (Optional) Enter any tags, select Inactive or Active execution, and click on Next.

  6. Configure the deployment options (setting a region is required) and click on Next.

  7. Review your settings, and click Submit.

  8. On Umbrella, navigate to Accounts > Linked account page, and click on Validate All Connection to validate a successful connection.


  1. You will start seeing recommendations the next time your invoice runs (which occurs automatically every day).


Connect Linked Accounts Based on Tagging

  1. From Umbrella's main page, click on Account.

  1. Click on the Cloud Accounts tab and copy the external ID value of your account.

  1. Log into the AWS console for the payer account: https://aws.amazon.com/

  2. Navigate to CloudFormation > Stacks and click on Create Stack.

  3. Choose the options as displayed below, upload the following file, and click on Next.

  4. Choose a name for the Stack, enter the external ID you copied in step #2, and click on Next.

  5. Click on Next.

  6. For each linked account that you want us to apply the policy with permissions for, add the following tag: Umbrella: onboarded

  7. On Umbrella, navigate to Accounts > Linked account page, and click on Validate All Connection to validate a successful connection.


  1. The next time your invoice runs (which occurs automatically every day), you will start seeing recommendations.


Manual Connection for Each Linked Account via the Umbrella UI

  1. In the AWS Console, log in to the linked account that you would like to connect to Umbrella.

  2. On the Umbrella platform, click your username (in the top right corner) and click Account.

  3. Click the Linked Accounts tab.

  1. Click Open AWS platform to connect in the relevant linked account row.
    You will be redirected to a CloudFormation stack creation page, where the Umbrella role will be created for the linked account.

  1. In the AWS Console, click Create Stack.
  2. On the Umbrella platform, click on Validate Connection to validate a successful connection.
    Note: In case you want to connect multiple linked accounts you can click on Validate All Connections

You should now see that the Verification Status is connected as displayed below.


What’s Next

With your permissions set, you're all set to kick off your cost reduction journey with our smart recommendations!

Did this page help you?