What you will be able to do
- Weigh what a Snowflake organization gives you and name the account types it can contain
- Explain how an organization gets its name, how it is renamed, and how it is deleted
- Find the regions enabled for an organization and create accounts only in those regions
- Create, list, rename and drop accounts in Snowsight or SQL, including the first ACCOUNTADMIN user
- Set parameters at the account level and explain how they become defaults for users, sessions and objects
- Perform the everyday organizational tasks: view the organization name, list its accounts and its organization account, and list the regions available to it
Key concept
Organization — A Snowflake object that sits above your accounts and links them all together. It lets an organization administrator create, view, rename and drop every account the business owns, across regions and cloud platforms, from one place.
1.What an organization is for, and what it contains
A business rarely stays at one Snowflake account. Production, development, a second region for disaster recovery, a partner-facing account: each is a separate account with its own users, roles, databases and warehouses. The organization is what ties them together. From it, organization administrators can view, create and manage all accounts across regions and cloud platforms.
The documentation lists the benefits: one view of every account, self-service account creation, data availability through replication and failover, data sharing with consumers across regions, and usage monitoring across all accounts. Organizations also make billing and other account administration simpler. The sources don't list costs as such. The trade-offs they do describe are that all accounts are billed together on one bill, and that the number of accounts is capped (covered below).
| Account type | Who uses it and for what |
|---|---|
| Organization account | Organization administrators, to manage multi-account organizations and to read premium views in the ORGANIZATION_USAGE schema |
| Regular Snowflake account | Normal workloads; trial accounts count as regular accounts |
| Snowflake Open Catalog account | Service admins and catalog admins, to manage catalogs defined in Snowflake Open Catalog |
Checkpoint 1 of 7· Match them up
Match each account type to its purpose
Tap a term, then the definition that fits it.
The organization account is special because organization administrators manage the whole organization from it and read the premium usage views there. Open Catalog accounts exist only to manage catalogs.
“Special account used by organization administrators to manage multi-account organizations and to access usage data from premium views in the ORGANIZATION_USAGE schema.”Source: docs.snowflake.com
Identifying which regions are available for your organization is one of the organizational tasks you should be able to do. An organization administrator can view the list of regions available for the organization in Snowsight or with SQL. In Snowsight, open Admin » Accounts, select + Account and browse the Region list. In SQL, run SHOW REGIONS, which lists all the regions in which accounts can be created.
The output gives the Snowflake region name, the cloud provider that hosts it, the cloud provider's own name for the region, and a human-readable display name. If the organization spans multiple region groups, the output also includes a region_group column. Regions limit only where data is stored and compute is provisioned; they do not limit where users can connect from.
2.Creating, naming and deleting an organization
So the exam task "create and name an organization" is mostly about knowing who does it. If you sign up self-service, an organization is created automatically, with a system-generated name, when the account is created. If you set up accounts with Snowflake personnel, Snowflake creates the organization with a custom name. Either way, you can add more accounts to it afterwards.
To see the name, an organization administrator runs SHOW ACCOUNTS or opens Admin » Accounts in Snowsight, where the organization name appears above the account names. Any role can call CURRENT_ORGANIZATION_NAME to get the organization of the current account.
Renaming an organization, for example replacing a system-generated name with a friendlier one, goes through Snowflake Support. When you ask, you decide whether users can keep using the original account URL for a while. If you keep it, it is dropped automatically after 90 days. Deleting an organization also ends with Support: you delete every account except the one you are working from, then contact Support to delete that last account and the organization.
Checkpoint 2 of 7· Check yourself
An administrator wants to replace the system-generated organization name with the company name. What do they do?
ALTER ACCOUNT ... RENAME TO renames accounts, not the organization. Organization renames go through Snowflake Support, which also asks whether to keep the old URL for 90 days.
“to change a system-generated name to a more user-friendly one, contact Snowflake Support.”Source: docs.snowflake.com
Putting these together, the organizational tasks you can perform yourself are:
- View the organization name and its accounts: SHOW ACCOUNTS, or Admin » Accounts in Snowsight (organization administrator). - Return the organization of the current account: the CURRENT_ORGANIZATION_NAME function (any role). - Find the organization's special account: SHOW ORGANIZATION ACCOUNTS lists the organization account of the organization. - Name the types of account in it: organization account, regular account (including trials) and Open Catalog account. - Remove an old organization URL early: after a rename you can delete it before the 90 days expire.
Tasks that change the organization itself, namely renaming it and deleting the last account and the organization, are done through Snowflake Support.
3.Which regions an organization can use
An organization can span clouds and regions, but not every region is open to it automatically. An organization administrator sees the enabled regions in one of two ways: in Snowsight, by opening Admin » Accounts, selecting + Account and browsing the Region list, or in SQL with SHOW REGIONS.
That list sets a hard limit on account creation. You can only create an account in a region enabled for your organization. To use any other region, you ask Snowflake Support for access.
Checkpoint 3 of 7· Check yourself
An organization administrator tries to create an account in a region that does not appear in SHOW REGIONS output. What is the correct next step?
Accounts can be created only in regions enabled for the organization, and Support enables additional ones.
“To request access to additional regions, contact Snowflake Support.”Source: docs.snowflake.com
4.Creating an account
The organization administrator manages each account's whole lifecycle, from creation to deletion. To create an account, select + Account under Admin » Accounts in Snowsight, or run CREATE ACCOUNT. You choose a cloud platform, a region and a Snowflake edition.
Three limits are worth knowing. An organization can have at most 25 On Demand accounts by default, or 100 if it has a capacity contract; Support can raise either limit. A new account becomes reachable only after DNS changes propagate, which takes about 30 seconds. And usage in every account appears on one bill.
The most important choice at creation time is the first user, who receives ACCOUNTADMIN. Mark it as a person and that user must enroll in MFA. Mark it as a service and it cannot authenticate with a password, so you must provide an RSA public key.
CREATE ACCOUNT my_admin
ADMIN_USER_TYPE = SERVICE
ADMIN_RSA_PUBLIC_KEY = 'MIIBIj...';Checkpoint 4 of 7· Fill the gap
This statement creates an account whose ACCOUNTADMIN is a human who must enroll in MFA. Which value fills the blank?
CREATE ACCOUNT my_admin ADMIN_USER_TYPE = ? ;ADMIN_USER_TYPE = PERSON marks the first ACCOUNTADMIN as a human and requires MFA enrollment. SERVICE is for non-human admins that authenticate with an RSA key.
Source: docs.snowflake.comSources2
5.Listing, renaming and dropping accounts
To list accounts, use Admin » Accounts in Snowsight, where you can search and filter both active and dropped accounts, or run SHOW ACCOUNTS.
Renaming an account gives it a new account URL. By default the original URL is kept so users can go on using it; you can delete saved URLs later. To make everyone switch to the new URL immediately, clear Save Current URL in Snowsight or set SAVE_OLD_URL to FALSE in SQL. A rename has no effect on replication and failover. Reader accounts can be renamed only with SQL.
Dropping an account removes it from the organization. Dropping is the last step of the account lifecycle that the organization administrator manages.
ALTER ACCOUNT original_acctname RENAME TO new_acctname;Checkpoint 5 of 7· Check yourself
An admin using ORGADMIN in account PROD runs ALTER ACCOUNT PROD RENAME TO PROD_EU and it fails. The organization has three accounts. What is the fix?
ORGADMIN cannot rename the account it is logged in to. Support is needed only when the organization has a single account.
“Organization administrators who are using the ORGADMIN role cannot rename an account while they are logged in to it”Source: docs.snowflake.com
Checkpoint 6 of 7· Exam question
A company runs three Snowflake accounts that were purchased independently by different departments. Finance wants consolidated credit and storage reporting plus one team that can create and retire accounts. What is the MOST appropriate approach?
Correct answer: C — Place all three accounts in one Snowflake organization and let ORGADMIN query ORGANIZATION_USAGE views and manage the account lifecycle
- A. Replication groups copy databases, users and roles, not the ACCOUNT_USAGE views, and ACCOUNTADMIN in one account has no authority over the others. This would not deliver consolidated reporting.
- B. Reader accounts are meant for consumers without a Snowflake account, and metering views in the SNOWFLAKE database cannot be shared this way. It would also add accounts to maintain instead of consolidating them.
- C. An organization groups accounts under one name, gives ORGADMIN lifecycle control over every member account, and exposes cross-account usage through the ORGANIZATION_USAGE schema. This meets both finance requirements directly.
- D. Role grants cannot cross account boundaries, so a finance role in one account can never receive privileges in another. IMPORTED PRIVILEGES only affects the account that holds the role.
6.Account-level parameters
Once an account exists, you control its behavior with parameters set through ALTER ACCOUNT. Most parameters are session parameters. A value set at the account level becomes the default for every user and session. Users can override it with ALTER USER, and sessions with ALTER SESSION. Object parameters work the same way: an account-level value becomes the default for objects created in the account.
One detail catches people out: SHOW PARAMETERS does not list account parameters by default. Some features are switched on only through an account parameter. For example, on Enterprise Edition, ACCOUNTADMIN can turn on periodic rekeying of encrypted data:
ALTER ACCOUNT SET PERIODIC_DATA_REKEYING = TRUE;Checkpoint 7 of 7· Check yourself
An account administrator sets a session parameter with ALTER ACCOUNT. A user then runs ALTER SESSION with a different value. Which value applies in that user's session?
Account-level values are defaults. Users and sessions can override session parameters.
“Users can run the ALTER SESSION command to override session parameters for the current session.”Source: docs.snowflake.com
Sources9
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.An administrator creates the organization with a SQL command and can rename it the same way.Why is that wrong?
Customers never create an organization directly. It is created automatically with the first account, or by Snowflake, and renaming or deleting it requires Snowflake Support.
2.Renaming an account breaks the old URL immediately, so users are locked out until they update their bookmarks.Why is that wrong?
By default the original URL is saved and keeps working. Users are forced onto the new URL only if you set SAVE_OLD_URL to FALSE or clear Save Current URL.
Covered in Listing, renaming and dropping accounts
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Organizations simplify account management and billing, Replication and Failover/Failback, Snowflake Secure Data Sharing, and other account administration tasks.”
↩︎ What an organization is for, and what it contains“If you keep the original account URL, it is automatically dropped after 90 days”
↩︎ Creating, naming and deleting an organization“Contact Snowflake Support to delete the last account and the organization.”
↩︎ Creating, naming and deleting an organization“Users with any role can execute the CURRENT_ORGANIZATION_NAME function to return the organization of the current account.”
↩︎ Creating, naming and deleting an organization“An organization is a first-class Snowflake object that links the accounts owned by your business entity.”
↩︎ Key concept“an organization is automatically created with a system-generated name when the account is created.”
↩︎ Exam trap 1“Special account used by organization administrators to manage multi-account organizations and to access usage data from premium views in the ORGANIZATION_USAGE schema.”
↩︎ Checkpoint“Snowflake customers never directly create an organization.”
↩︎ Prediction“to change a system-generated name to a more user-friendly one, contact Snowflake Support.”
↩︎ Checkpoint - 2.
“You will be billed for usage in all of your accounts on a single bill.”
↩︎ What an organization is for, and what it contains“You can only create an account in a region that is enabled for your organization.”
↩︎ Which regions an organization can use“By default, the maximum number of On Demand accounts in an organization is 25.”
↩︎ Creating an account“A service-type ACCOUNTADMIN cannot use passwords to authenticate, and must specify an ADMIN_RSA_PUBLIC_KEY during account creation.”
↩︎ Creating an account“To request access to additional regions, contact Snowflake Support.”
↩︎ Checkpoint - 3.
“An organization administrator can view a list of regions available for an organization through Snowsight or using SQL:”
↩︎ What an organization is for, and what it contains“An organization administrator can view a list of regions available for an organization through Snowsight or using SQL:”
↩︎ Which regions an organization can use - 4.
“Lists all the regions in which accounts can be created.”
↩︎ What an organization is for, and what it contains - 5.https://docs.snowflake.com/en/sql-reference/sql-allOfficial docs
“Lists the organization account of the organization.”
↩︎ Creating, naming and deleting an organization - 6.
“You can search and filter active and dropped accounts in your organization.”
↩︎ Listing, renaming and dropping accounts - 7.
“Renaming an account has no effect on replication and failover.”
↩︎ Listing, renaming and dropping accounts“set the optional SAVE_OLD_URL parameter to FALSE when renaming the account.”
↩︎ Exam trap 2“Organization administrators who are using the ORGADMIN role cannot rename an account while they are logged in to it”
↩︎ Checkpoint - 8.
“Removes an account from the organization.”
↩︎ Listing, renaming and dropping accounts - 9.
“Account administrators can run the ALTER ACCOUNT command to set session parameters for the account.”
↩︎ Account-level parameters“By default, account parameters are not displayed in the output of SHOW PARAMETERS.”
↩︎ Account-level parameters“Users can run the ALTER SESSION command to override session parameters for the current session.”
↩︎ Checkpoint