4
Most read
5
Most read
7
Most read
Govern and orchestrate multi-account environments
AWS Control Tower
Jackson Oliveira
@cyberjso
The multiple accounts approach
➢ Isolate different workloads and allow distinct operation
models
➢ Compliance and security
➢ Better cost management
➢ Speed up innovation
➢ Smaller blast radious
Organization units
Organization units - limitations
➢ Operate at scale (dozens, hundreds or thousands)
○ Hard to guarantee compliance
○ Maintenance. How to apply changed on all of them?
○ Security. Difficult to track suspicious activities
○ Cost. Dedicated engineers and teams to maintain and evolve
the structure, difficult to self-serve engineers
AWS Control Tower Orchestration
Organization units
AWS SSO SCP
Service
Catalog
Parameter store
Cloudformation
AWS Control Tower
S3 VPC Config
Well
ARchitected
Best
Practices
AWS Control Tower - Main features
➢ Single view of the entire multi-account architecture
➢ Govern multiple-accounts from blueprints (landing zone)
➢ Enforces global rules (guardrails) for all accounts
➢ Apply changes from a central place
➢ Automates the account creation process at scale
➢ Customizable
AWS Control Tower - Typical setup
AWS Control Tower - Landing zone
➢ Central place where configuration for other accounts are set
➢ Resides on the master account
➢ Define what goes inside each OU/account
➢ Contains all the dashboards
AWS Control Tower
AWS Control Tower - Takeaways
➢ Existent accounts can be added into the structure after the initial
setup.
➢ For small environments can be an overkill
➢ Can be customizable via terraform
➢ Errors can be hard to track sometimes
➢ Once defined, master account cannot be changed
➢ Not recommended for envs that requires too much customizations
➢ Errors are hard to troubleshoot sometimes
Govern and orchestrate multi-account environments
AWS Control Tower
Jackson Oliveira
@cyberjso
Thank you!

More Related Content

PPTX
AWS Landing Zone - Architecting Security and Governance.pptx
PDF
Steven Seaney - Simplifying and Streamlining AWS Control Tower Deployments
PDF
Steven Seaney - Simplifying and Streamlining AWS Control Tower Deployments
PPTX
Ghost Environment
PPTX
Governance Automation in AWS (30 March 2022, ICC - Sydney)
PPTX
Infrastructure Provisioning & Automation For Large Enterprises
PPTX
Intigua review aws integration
PDF
Interop ITX: Moving applications: From Legacy to Cloud-to-Cloud
AWS Landing Zone - Architecting Security and Governance.pptx
Steven Seaney - Simplifying and Streamlining AWS Control Tower Deployments
Steven Seaney - Simplifying and Streamlining AWS Control Tower Deployments
Ghost Environment
Governance Automation in AWS (30 March 2022, ICC - Sydney)
Infrastructure Provisioning & Automation For Large Enterprises
Intigua review aws integration
Interop ITX: Moving applications: From Legacy to Cloud-to-Cloud

Similar to AWS Control Tower (18)

PDF
Secure Cloud governance - AWS landing zone
PPTX
Aws disaster recovery
PPTX
CloudStackFinalProject
PPTX
On-Prem to All-In: How Versent Leads Successful AWS Migrations
PDF
Aws organizations
PPTX
AWS Solution Architect Associate Report
PPTX
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
PPTX
AWS Well Architected Framework
PPTX
ACDKOCHI19 - Journey from a traditional on-prem Datacenter to AWS: Challenges...
PPTX
Deploying High Availability and Business Resilient R12 Applications over the ...
PDF
AWSome day 2018 - scalability and cost optimization with container services
PPTX
Weaveworks at AWS re:Invent 2016: Operations Management with Amazon ECS
PPTX
How to Build a Multi-DC Cassandra Cluster in AWS with OpsCenter LCM
PDF
Segurança de Ponta a Ponta na AWS
PPTX
Hack proof your aws cloud cloudcheckr_040416
PDF
OpenStack- A ringside view of Services and Architecture
PPTX
Aws disaster recovery
PPTX
Hackproof Your Cloud: Responding to 2016 Threats
Secure Cloud governance - AWS landing zone
Aws disaster recovery
CloudStackFinalProject
On-Prem to All-In: How Versent Leads Successful AWS Migrations
Aws organizations
AWS Solution Architect Associate Report
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
AWS Well Architected Framework
ACDKOCHI19 - Journey from a traditional on-prem Datacenter to AWS: Challenges...
Deploying High Availability and Business Resilient R12 Applications over the ...
AWSome day 2018 - scalability and cost optimization with container services
Weaveworks at AWS re:Invent 2016: Operations Management with Amazon ECS
How to Build a Multi-DC Cassandra Cluster in AWS with OpsCenter LCM
Segurança de Ponta a Ponta na AWS
Hack proof your aws cloud cloudcheckr_040416
OpenStack- A ringside view of Services and Architecture
Aws disaster recovery
Hackproof Your Cloud: Responding to 2016 Threats
Ad

More from Jackson dos Santos Olveira (20)

PDF
PDF
An introduction to predictionIO
PDF
Introduction to HashiCorp Consul
PDF
Apache mahout - introduction
PDF
Managing computational resources with Apache Mesos
PDF
Introduction to CFEngine
PDF
PDF
Jboss Teiid - The data you have on the place you need
PDF
Apache PIG introduction
PPSX
Jboss AS7 New Main Features
PPSX
Celery Introduction
PPT
Elastic search introduction
PPT
Presentation about ClosureScript fraemework
An introduction to predictionIO
Introduction to HashiCorp Consul
Apache mahout - introduction
Managing computational resources with Apache Mesos
Introduction to CFEngine
Jboss Teiid - The data you have on the place you need
Apache PIG introduction
Jboss AS7 New Main Features
Celery Introduction
Elastic search introduction
Presentation about ClosureScript fraemework
Ad

Recently uploaded (20)

PDF
INTERSPEECH 2025 「Recent Advances and Future Directions in Voice Conversion」
PDF
SaaS reusability assessment using machine learning techniques
PPTX
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
PPTX
Microsoft User Copilot Training Slide Deck
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
DOCX
Basics of Cloud Computing - Cloud Ecosystem
PDF
Early detection and classification of bone marrow changes in lumbar vertebrae...
PPTX
SGT Report The Beast Plan and Cyberphysical Systems of Control
PDF
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
PPT
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
PPTX
Configure Apache Mutual Authentication
PPTX
future_of_ai_comprehensive_20250822032121.pptx
PPTX
Internet of Everything -Basic concepts details
PPTX
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
Rapid Prototyping: A lecture on prototyping techniques for interface design
PDF
Statistics on Ai - sourced from AIPRM.pdf
PDF
giants, standing on the shoulders of - by Daniel Stenberg
PDF
sbt 2.0: go big (Scala Days 2025 edition)
PDF
Aug23rd - Mulesoft Community Workshop - Hyd, India.pdf
INTERSPEECH 2025 「Recent Advances and Future Directions in Voice Conversion」
SaaS reusability assessment using machine learning techniques
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
Microsoft User Copilot Training Slide Deck
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
Basics of Cloud Computing - Cloud Ecosystem
Early detection and classification of bone marrow changes in lumbar vertebrae...
SGT Report The Beast Plan and Cyberphysical Systems of Control
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
Galois Field Theory of Risk: A Perspective, Protocol, and Mathematical Backgr...
Configure Apache Mutual Authentication
future_of_ai_comprehensive_20250822032121.pptx
Internet of Everything -Basic concepts details
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
Improvisation in detection of pomegranate leaf disease using transfer learni...
Rapid Prototyping: A lecture on prototyping techniques for interface design
Statistics on Ai - sourced from AIPRM.pdf
giants, standing on the shoulders of - by Daniel Stenberg
sbt 2.0: go big (Scala Days 2025 edition)
Aug23rd - Mulesoft Community Workshop - Hyd, India.pdf

AWS Control Tower

  • 1. Govern and orchestrate multi-account environments AWS Control Tower Jackson Oliveira @cyberjso
  • 2. The multiple accounts approach ➢ Isolate different workloads and allow distinct operation models ➢ Compliance and security ➢ Better cost management ➢ Speed up innovation ➢ Smaller blast radious
  • 4. Organization units - limitations ➢ Operate at scale (dozens, hundreds or thousands) ○ Hard to guarantee compliance ○ Maintenance. How to apply changed on all of them? ○ Security. Difficult to track suspicious activities ○ Cost. Dedicated engineers and teams to maintain and evolve the structure, difficult to self-serve engineers
  • 5. AWS Control Tower Orchestration Organization units AWS SSO SCP Service Catalog Parameter store Cloudformation AWS Control Tower S3 VPC Config Well ARchitected Best Practices
  • 6. AWS Control Tower - Main features ➢ Single view of the entire multi-account architecture ➢ Govern multiple-accounts from blueprints (landing zone) ➢ Enforces global rules (guardrails) for all accounts ➢ Apply changes from a central place ➢ Automates the account creation process at scale ➢ Customizable
  • 7. AWS Control Tower - Typical setup
  • 8. AWS Control Tower - Landing zone ➢ Central place where configuration for other accounts are set ➢ Resides on the master account ➢ Define what goes inside each OU/account ➢ Contains all the dashboards
  • 10. AWS Control Tower - Takeaways ➢ Existent accounts can be added into the structure after the initial setup. ➢ For small environments can be an overkill ➢ Can be customizable via terraform ➢ Errors can be hard to track sometimes ➢ Once defined, master account cannot be changed ➢ Not recommended for envs that requires too much customizations ➢ Errors are hard to troubleshoot sometimes
  • 11. Govern and orchestrate multi-account environments AWS Control Tower Jackson Oliveira @cyberjso Thank you!