Sketio

AWS Multi-Account Architecture with Control Tower

Updated

An AWS account is a strong boundary: its own resources, its own limits, its own bill and its own set of identities. Teams that run more than a handful of workloads usually split them across accounts, for example one per environment or per team, and manage the accounts together with AWS Organizations.

AWS Control Tower sets this up with a recommended structure, called a landing zone. It builds on AWS Organizations, AWS Service Catalog and AWS IAM Identity Center, creates the shared accounts for logs and audit, applies controls to groups of accounts, and lets teams request new accounts from a template. This diagram shows that structure and where people and policies come in.

Management accountSecurity OUWorkloads OULog archive accountAudit accountProduction accountDevelopment accountsign inEngineersOrganizationsControl TowerIAM Identity CenterLog bucketCross-account accessProduction appsDevelopment appsSCPsbuilds on

Scroll sideways to see the whole diagram

AWS Multi-Account Architecture with Control Tower. Open it in Sketio to change it.

Start from this diagram and edit it on your own board.

By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.

What each part does

Engineers
The people who build and operate the workloads. They sign in once and are given access to the accounts they need.
Management account
The account that owns the organization. It creates and invites accounts, hosts Control Tower and IAM Identity Center, and receives the consolidated bill. AWS recommends keeping production workloads out of it. Service control policies do not apply to it.
Organizations
AWS Organizations groups accounts into organizational units (OUs) and attaches policies to them. It is where accounts are created and where service control policies live.
Control Tower
Sets up and governs the landing zone. It creates the Security OU and its accounts, enables the controls you choose, and offers Account Factory to provision new accounts from a template.
IAM Identity Center
Single sign-on for people. Users and groups are given access to accounts through permission sets, so nobody needs a separate IAM user in each account.
Security OU
The OU that Control Tower creates for the shared accounts. It contains the log archive account and the audit account.
Log archive account
A shared account that works as the repository for logs of API activity and resource configuration from every account in the landing zone. Few people need access to it.
Log bucket
Where the logs are stored, in Amazon S3. Keeping them in an account of their own, away from the accounts that produce them, protects the record of what happened.
Audit account
A restricted shared account designed to give your security and compliance teams read and write access to all accounts in the landing zone.
Cross-account access
How the audit account reaches the others: programmatically, through a role that is granted to Lambda functions only. The audit account does not let anyone sign in to the other accounts manually.
Workloads OU
An OU you create for member accounts that run applications. Controls and policies attached to it apply to every account inside, including accounts added later.
Production account
Runs production workloads, separated from development by an account boundary rather than by naming conventions.
Production apps
Your production applications and data. Their permissions come from the account and from the controls on the OU.
Development account
Where teams build and test. Its own limits and budget keep experiments away from production.
Development apps
Test environments and experiments, with looser permissions than production but the same guardrails from the OU.
SCPs
Service control policies set the maximum permissions available in the accounts under an OU. They never grant access by themselves, and they do not apply to the management account. In Control Tower, preventive controls are implemented with SCPs.

How accounts, people and policies fit together

  1. The management account owns the organization and runs Organizations, Control Tower and IAM Identity Center.
  2. Control Tower builds the landing zone: it creates the Security OU with the log archive and audit accounts, and enables the controls you select.
  3. You add OUs for your own needs, such as Workloads, and new accounts are created in them with Account Factory.
  4. SCPs and other controls are attached to an OU and apply to every account in it. Preventive controls block an action, and detective controls find resources that break a rule.
  5. Each account sends its API activity and configuration logs to the log archive account. The audit account gives the security and compliance teams programmatic access across accounts.
  6. Engineers sign in once through IAM Identity Center and choose an account and a permission set, for example read-only for production and administrator for development.

When to use it

Common variations

Add a Sandbox OU

The Control Tower documentation lists a Sandbox OU among the OUs of a landing zone, created when you set it up. Use an OU like it for individual experimentation, with tight budgets and strong preventive controls.

Add more OUs

Add OUs for infrastructure, policy staging or a business unit. Controls are applied per OU, so group accounts by the rules they share.

Use an existing organization

You can register an existing OU with Control Tower and enroll existing accounts, so you do not have to start from nothing. OUs created outside Control Tower cannot have its controls until they are registered.

Layer the controls

Control Tower has preventive controls (SCPs and resource control policies), detective controls (AWS Config rules) and proactive controls (CloudFormation hooks that check a template before it is deployed). Start with the mandatory ones and add the others as your rules become clear.

Make it yours

Rename the OUs and accounts to match how your company is organised, and decide which SCPs and controls each OU gets.

Opens this diagram as a board you can edit.

By continuing, you agree to the Terms of Service and Privacy Policy, including sending images of your strokes, diagram labels and similar data to providers in the United States (Cloudflare, Inc. and TypeSafe AI, Inc.) for AI conversion.

All templates