

# Work with cross-account resources in Global Accelerator
Work with cross-account resources

If your account, or an accelerator that you have permission to access, is specified as a principal in a cross-account attachment in AWS Global Accelerator, you can use resources that have been shared with you from another account.

For example, you can select bring your own IP (BYOIP) addresses as static IP addresses when you create an accelerator, or you can add endpoints to accelerator endpoint groups for an accelerator. The resources that you can add must also be specified in the attachment.

The following sections include the steps to add or remove cross-account attachments in Global Accelerator.

**Topics**
+ [Add cross-account BYOIP addresses](cross-account-resources.add-byoip.md)
+ [Add cross-account endpoints](cross-account-resources.add-endpoints.md)
+ [Remove cross-account endpoints](cross-account-resources.remove-endpoints.md)

# Add a cross-account BYOIP address in Global Accelerator
Add cross-account BYOIP addresses

Follow the steps in this section to configure cross-account bring your own IP (BYOIP) ID addresses using the Global Accelerator console. 

This section explains how to use a BYOIP IP address by using the AWS Global Accelerator console. To learn about using API operations with Global Accelerator, see the [AWS Global Accelerator API Reference](https://docs.aws.amazon.com/global-accelerator/latest/api/Welcome.html).

You can change the BYOIP addresses that you use for your accelerator, but some restrictions apply. For more information, see [How to update an accelerator to change an IP address](using-byoip.update-accelerator.md#using-byoip.update-accelerator.how-to).

# To use a cross-account BYOIP IP address


1. Open the Global Accelerator console at [ https://console.aws.amazon.com/globalaccelerator/home](https://console.aws.amazon.com/globalaccelerator/home). 

1. Choose **Create accelerator**.

1. Provide a name for your accelerator.

1. Select an **Accelerator type**.

1. For **IP address type**, select **IPv4**.

1. Select the **Use a static IP address from a CIDR authorized for cross-account** check box.

1. Select the account ID for the owner of the cross-account attachment that specifies you as a principal and that includes the BYOIP address block that has been shared with you.

   Note that because you must choose one account to select addresses from, if you select two BYOIP IP addresses when you create an accelerator, the IP addresses must have the same owner and be authorized in the same cross- account attachment.

1. Specify one or both static IP addresses for your accelerator.
   + For each static IP address, choose the IP address pool to use.
**Note**  
You must choose a different IP address pool for each static IP address. This restriction is because Global Accelerator assigns each address range to a different network zone, for high availability.
   + If you chose your own IP address pool, also choose a specific IP address from the pool. If you choose the default Amazon IP address pool, Global Accelerator assigns a specific IP address to your accelerator.

1. Optionally, add one or more tags to help you identify your accelerator resources.

1. Choose **Next** to add listeners, endpoint groups, and endpoints.

# Add cross-account endpoints in AWS Global Accelerator
Add cross-account endpoints

Follow the steps in this section to add a cross-account endpoints using the Global Accelerator console. 

This section explains how to add cross-account endpoints by using the AWS Global Accelerator console. To learn about using API operations with Global Accelerator, see the [AWS Global Accelerator API Reference](https://docs.aws.amazon.com/global-accelerator/latest/api/Welcome.html).

# To add a cross-account endpoint


1. When you create or update an accelerator, in the **Endpoints** section, choose **Add endpoint**.

1. On the **Add endpoints** page, select **Add a resource specified in a cross-account attachment**.

1. In the drop-down menu, select an AWS account that has created a cross-account attachment that includes you or the accelerator as a principal.

1. For **Endpoint type**, choose the type of resource that you want to add.

   Note that only the resource types included in the cross-account attachment appear in the drop-down menu.

1. For **Endpoint**, choose resource that you want to add.

   Note that only resources that are included in the cross-account attachment appear in the drop-down menu. To see resources that are not enabled by a cross-account attachment, clear the **Add a resource specified in a cross-account attachment** check box.

# Remove a cross-account endpoint in Global Accelerator
Remove cross-account endpoints

Follow the steps in this section to remove a cross-account endpoints using the Global Accelerator console. 

This section explains how to remove cross-account endpoints by using the AWS Global Accelerator console. To learn about using API operations with Global Accelerator, see the [AWS Global Accelerator API Reference](https://docs.aws.amazon.com/global-accelerator/latest/api/Welcome.html).

# To remove a cross-account endpoint


1. When you create or update an accelerator, on the **Endpoint group** details page, choose the endpoint that you want to remove.

1. Choose **Remove**.