AWS Control Tower in multi AWS account scenarios
Rating: 9 out of 10
IncentivizedUse Cases and Deployment Scope
AWS Control Tower allows me to provision predefined compliant and secure AWS accounts in an automated fashion
Pros
- AWS Control Tower integrates with AWS organizations
- AWS Control Tower provides Account Factory to provision preconfigured AWS accounts
- AWS Control Tower helps to isolate workloads and billing via AWS accounts separation
- AWS Control Tower supports data residency controls out of the box
- AWS Control Tower supports post provisioning actions to newly provisioned AWS accounts: for example it can trigger enabling VPC flow logs in the new account
Cons
- If possible it would be nice to see an automated option to close AWS accounts created with the Account Factory
Likelihood to Recommend
Multi - account scenario is perfect example where AWS Control Tower should be used - to separate workloads in individual accounts. I.E. development and production in different accounts with separate billing