CertSafari
    Snowflake SnowPro Advanced: Administrator (ADA-C02)· Lessons

    Domain 1 · Lesson 1/24

    How Organization-Level Changes Affect Snowflake Accounts

    Manage administrative roles

    10 min read
    4.43% of exam
    6 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Predict what happens to account URLs when an account or an organization is renamed
    • Explain how dropping an account affects its data, shares, reader accounts and billing, and what to do before running DROP ACCOUNT
    • Describe the users and roles that appear in a regular account when an organization user group is imported
    • Anticipate the side effects of moving the organization account to another region

    1.Renaming accounts and organizations: what happens to URLs

    Organization administrators manage the full lifecycle of every account in the organization: creating, listing, renaming, changing the edition and dropping. Most of these actions change something that users, connections or other accounts depend on, so before running one you need to know its effect inside the account. Renaming is the easiest case. Renaming an account gives it a new URL. By default, Snowflake also keeps the original URL, so existing connections keep working. Renaming has no effect on replication and failover.

    Renaming an account (run by an organization administrator from a different account)sql
    ALTER ACCOUNT original_acctname RENAME TO new_acctname;

    Changes to the organization itself work differently. Snowflake Support handles these changes: renaming the organization, merging it with another organization, or moving an account to a different organization. Each one also gives the affected accounts new URLs. If the original URL is kept, it is called the "old organization URL", and it expires after 90 days instead of lasting indefinitely. That 90-day limit is something to plan for, because any driver or integration still using the old URL stops working when it expires.

    Old URLs after a rename: account-level vs organization-level change
    ChangeOriginal URL kept?How long it worksCommand to remove it early
    Account renamedSaved by default; can be deleted during the renameNo limitALTER ACCOUNT my_account1 DROP OLD URL;
    Organization renamed, merged, or account moved to another organizationSaved or deleted by Snowflake Support90 days, then deletedALTER ACCOUNT my_account1 DROP OLD ORGANIZATION URL;

    Checkpoint 1 of 7· Check yourself

    An organization administrator renames an account and keeps the default settings. How long can users keep connecting with the original account URL?

    Sources12

    2.Dropping an account: grace period, shares and billing

    DROP ACCOUNT is the organization-level change with the biggest effect on what is inside an account. The account is not deleted immediately. It enters a grace period, set by the administrator, of 3 to 90 days. During that time the account is locked to block activity, and an organization administrator can restore it. Two details are commonly misunderstood. The organization keeps paying for the account's storage throughout the grace period. And the grace period is not the same thing as the Time Travel data retention period.

    Checkpoint 2 of 7· Fill the gap

    Complete the command that drops an account but allows 14 days to restore it

    DROP ACCOUNT my_account  ?  = 14;

    Other accounts feel the effect of a drop straight away. Shares from the dropped account stop working the moment it is dropped. Reader accounts it created are dropped too, and are deleted together with it. An account that has active listings, whether shared to specific consumers or published on the Snowflake Marketplace, cannot be dropped at all. You must first remove those listings and drop the shares behind them. The provider's organization administrator should also tell consumers that they will lose access. There are also two operational rules. You cannot drop the account you are currently logged in to. And because the name stays reserved during the grace period, rename the account before dropping it if you want to reuse the name. A restored account is unlocked and behaves as if it had never been dropped.

    Restoring a dropped account that is still within its grace periodsql
    UNDROP ACCOUNT myaccount123;

    Checkpoint 3 of 7· Check yourself

    An account that shares a database with consumers through a direct share (no listing) is dropped with a 30-day grace period. What happens to the consumers' access?

    Checkpoint 4 of 7· Exam question

    A nightly ETL pipeline authenticates as a service user whose only role is ACCOUNTADMIN, because it was the quickest way to get past permission errors. A security review flags this. What is the MOST appropriate remediation?

    Sources3

    3.Organization users: global identities that become account objects

    Organization administrators can also create objects that end up inside regular accounts. Instead of creating the same person or service separately in every account, the global organization administrator creates an organization user in the organization account. An organization user is either a PERSON or a SERVICE type. The administrator groups organization users into organization user groups and controls which accounts can see each group. Account administrators do not add organization users one by one. They import a group, and its members become users in their account.

    Checkpoint 5 of 7· Put it in order

    Put the organization-user workflow in order

    1. 1.Create an organization user group
    2. 2.Check for and resolve any conflicts
    3. 3.Make the group available to regular accounts
    4. 4.In a regular account, import the organization user group
    5. 5.Add the organization users to the group
    6. 6.Create an organization user for each person or service

    Importing a group creates account-level objects. Snowflake creates a role with the same name as the group and grants it to every imported user. Account administrators can then grant privileges to that role. Whether they can also grant the imported role to their own local roles depends on how the group was created: the organization administrator must have set IS_GRANTABLE = TRUE. If one organization user belongs to several imported groups, the account gets a single local user who holds the roles from all of those groups. Some limits are set at the organization level. An organization user's basic properties cannot be changed in a regular account after import, and a user's type cannot be changed after the organization user is created.

    An organization user group whose imported role can be granted to local rolessql
    USE ROLE GLOBALORGADMIN;
    
    CREATE ORGANIZATION USER GROUP data_engineers_group
     IS_GRANTABLE = TRUE;

    Checkpoint 6 of 7· Check yourself

    An account administrator imports the organization user group data_stewards. Which account-level object does Snowflake create alongside the users?

    Sources4

    4.Moving the organization account and where metadata ends up

    The organization account can move between regions within the PUBLIC region group or a VPS region group. Snowflake does the move with replication groups. That has two consequences: only objects that can be replicated move with the account, and the move incurs replication costs. It happens in two steps. You start the move, verify the replicated data, and then commit it with a grace period, after which the original organization account is deleted. Afterwards, the ORGANIZATION_USAGE views must be repopulated, which can take up to a week.

    Checkpoint 7 of 7· Put it in order

    Put the steps for moving the organization account to a new region in order

    1. 1.Verify that the data was successfully replicated in the new region
    2. 2.Call SYSTEM$INITIATE_MOVE_ORGANIZATION_ACCOUNT from the organization account
    3. 3.Call SYSTEM$COMMIT_MOVE_ORGANIZATION_ACCOUNT with a grace period

    Some organization-level features move metadata across regions even when no account is moved. Premium views can copy metadata from a regular account's region into the organization account's region. Organization-level objects such as organization users can carry metadata from the organization account's region into any account that imports them. This matters for hybrid organizations, meaning those with accounts in both a U.S. SnowGov Region and a commercial region. For them, Snowflake recommends creating the organization account in the regulated region and keeping sensitive or regulated data out of organization-level objects.

    Sources5

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.During a dropped account's grace period nothing is billed, and the grace period is just the Time Travel retention window.Why is that wrong?

      Storage is still billed during the grace period, and the grace period (3–90 days, set at DROP time) is separate from Time Travel retention.

      Covered in Dropping an account: grace period, shares and billing

    2. 2.After an organization is renamed, a saved original URL keeps working indefinitely, just as it does after an account rename.Why is that wrong?

      Old organization URLs are deleted after 90 days. Only URLs saved during an account rename have no time limit.

      Covered in Renaming accounts and organizations: what happens to URLs

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “When an account is renamed, Snowflake creates a new account URL that is used to access the account.”
      ↩︎ Renaming accounts and organizations: what happens to URLs
      “Renaming an account has no effect on replication and failover.”
      ↩︎ Renaming accounts and organizations: what happens to URLs
    2. 2.
      “If you keep the original account URL, it is automatically dropped after 90 days”
      ↩︎ Renaming accounts and organizations: what happens to URLs
    3. 3.
      “Once an account is dropped, it is locked to prevent activity during the grace period.”
      ↩︎ Dropping an account: grace period, shares and billing
      “The grace period is not the same as the data retention period of Time Travel.”
      ↩︎ Dropping an account: grace period, shares and billing
      “Reader accounts are dropped and then deleted at the same time as the provider account.”
      ↩︎ Dropping an account: grace period, shares and billing
      “You cannot drop an account that has active listings shared to specific consumers or listings published on the Snowflake Marketplace.”
      ↩︎ Dropping an account: grace period, shares and billing
      “As a workaround, rename the account before dropping it.”
      ↩︎ Dropping an account: grace period, shares and billing
      “An organization continues to pay for the cost of account storage during the grace period.”
      ↩︎ Exam trap 1
      “Shares stop working. Consumers lose access to data shared by the account.”
      ↩︎ Checkpoint
    4. 4.
      “Each user imported from the organization user group is granted this role.”
      ↩︎ Organization users: global identities that become account objects
      “Because the administrator set IS_GRANTABLE=TRUE, the account administrator will be able to grant the role created from the organization user group”
      ↩︎ Organization users: global identities that become account objects
      “If the administrator imports multiple organization user groups that contain the same organization user, only one local user is created”
      ↩︎ Organization users: global identities that become account objects
      “Import the organization user group into the account. Check for and resolve any conflicts.”
      ↩︎ Checkpoint
      “When the account administrator imports an organization user group into a regular account, Snowflake creates an access control role of the same name.”
      ↩︎ Checkpoint
    5. 5.
      “the views in the ORGANIZATION_USAGE schema must be repopulated with data, a process that can take up to one week.”
      ↩︎ Moving the organization account and where metadata ends up
      “Features associated with an organization account might result in metadata moving from one region to another.”
      ↩︎ Moving the organization account and where metadata ends up
      “Call the SYSTEM$INITIATE_MOVE_ORGANIZATION_ACCOUNT function from the organization account to start the process of moving it.”
      ↩︎ Checkpoint

    Also cited

    Ready to test yourself?

    Practise the 16 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.