This operation can be called only by the following principals when they
also have the relevant IAM permissions:
The user who calls the API for an invitation to join must have the
organizations:AcceptHandshake
permission. If you enabled all
features in the organization, the user must also have the
iam:CreateServiceLinkedRole
permission so that AWS Organizations
can create the required service-linked role named
AWSServiceRoleForOrganizations
. For more information, see AWS Organizations and Service-Linked Roles
in the AWS Organizations User Guide.
For more information about invitations, see Inviting an AWS Account to Join Your Organization
in the AWS Organizations User Guide. For more information about
requests to enable all features in the organization, see Enabling All Features in Your Organization
in the AWS Organizations User Guide.
After you accept a handshake, it continues to appear in the results of
relevant APIs for only 30 days. After that, it's deleted.