Skip to content

AWS Control Tower Landing Zone

Shailesh Gupta edited this page Aug 10, 2024 · 1 revision

AWS Control Tower Landing Zone Setup

Prerequisites:

  • Account:
    • Management Account (Master Account)
    • Email/DL for Log archive account
    • Email/DL for Audit account
  • Other Requirements:
    • Service Quotas (AWS Service Quotas)
    • Single AWS Organization
    • Trusted Access

Steps to Set Up AWS Landing Zone Using AWS Control Tower

  1. Log In as Administrator IAM User
  2. Create Landing Zone Using AWS Control Tower
  3. Set AWS Account Root User Password and Enable MFA
  4. Log In Via Control Tower Administrator User
  5. Configure Multi-Factor Authentication (MFA) Requirements
  6. Enable MFA via AWS SSO for Control Tower Administrator User
  7. Receive and Process AWS Email Messages
  8. Review Role of New AWS Accounts
  9. Disable Account Factory VPC Provisioning
  10. Review AWS Control Tower Best Practices for Administrators

Log In as Administrator IAM User or Root User

AWS Managment Console

Create Landing Zone Using AWS Control Tower

Navigate to AWS Control Tower

Create Landing Zone AWS Control Tower Setup

Configure Regions

Review pricing and select Regions (Pricing, Home Region, Additional Region, Region To Deny)

  • Home Region

    This is the AWS Region where shared resources will be provisioned. You cannot change the home Region after the landing zone is set up, but you can add more Regions to govern.

  • Additional Regions for governance

    You can optionally choose additional Regions for AWS Control Tower to govern.

  • Region deny setting

    If you have data residency requirements, you can optionally choose to enable a Region deny service control policy (SCP) to deny access in Regions that aren't selected.

Configure Regions

Configure Organizational Units (OUs)

Configure OUs

Configure Shared Accounts

Configure Shared Accounts

Additional Configurations

  • AWS account access configuration

    You can optionally choose to manage account access yourself or accept the default IAM Identity Center setup in AWS Control Tower.

  • AWS Cloud Trail Configuration

    You can optionally choose to manage CloudTrail in your organization yourself or accept the default CloudTrail setup from AWS Control Tower. The default setting enables an organization-level trail for management events in your Log Archive account.

  • Log Configuration for Amazon S3

    You can optionally configure log retention for the Log Archive S3 bucket or accept the default retention periods.

  • KMS encryption

    You can optionally enable encryption for AWS Control Tower resources by using an AWS Key Management Service (AWS KMS) customer managed key. If you enable encryption, you are asked to specify the key name or Amazon Resource Name (ARN) of the customer managed key to be used.

Additional Configurations

Review and Set Up Landing Zone

Review Landing Zone

Wait for the Landing Zone setup to complete

Set Up Landing Zone