AWS Control Tower
Customers who are now looking to set up a landing zone in accordance with the updated architectural best practices should use the new AWS Control Tower. This service automates the setup of a new landing zone using the latest blueprints. Some AWS accounts created as part of this landing zone include the following:
- Creation of an AWS Organizations and multi-account setup
- Identity and access management with AWS Single Sign-On (SSO) default directory services
- Account federation using SSO
- Centralized logging using AWS CloudTrail and AWS Config
The landing zone deployed by AWS Control Tower comes configured with recommended security policies called guardrails and customers can choose how their accounts are configured to comply with their overall organizational policies.
In this section, we looked at two services that can be used easily to architect your multi-account architecture. If this was to be carried out manually, it would be time-consuming...