-
Notifications
You must be signed in to change notification settings - Fork 3
AWS Control Tower Landing Zone
- Account:
- Management Account (Master Account)
- Email/DL for Log archive account
- Email/DL for Audit account
- Other Requirements:
- Service Quotas (AWS Service Quotas)
- Single AWS Organization
- Trusted Access
- Log In as Administrator IAM User
- Create Landing Zone Using AWS Control Tower
- Set AWS Account Root User Password and Enable MFA
- Log In Via Control Tower Administrator User
- Configure Multi-Factor Authentication (MFA) Requirements
- Enable MFA via AWS SSO for Control Tower Administrator User
- Receive and Process AWS Email Messages
- Review Role of New AWS Accounts
- Disable Account Factory VPC Provisioning
- Review AWS Control Tower Best Practices for Administrators
Review pricing and select Regions (Pricing, Home Region, Additional Region, Region To Deny)
-
This is the AWS Region where shared resources will be provisioned. You cannot change the home Region after the landing zone is set up, but you can add more Regions to govern.
-
You can optionally choose additional Regions for AWS Control Tower to govern.
-
If you have data residency requirements, you can optionally choose to enable a Region deny service control policy (SCP) to deny access in Regions that aren't selected.
-
You can optionally choose to manage account access yourself or accept the default IAM Identity Center setup in AWS Control Tower.
-
You can optionally choose to manage CloudTrail in your organization yourself or accept the default CloudTrail setup from AWS Control Tower. The default setting enables an organization-level trail for management events in your Log Archive account.
-
You can optionally configure log retention for the Log Archive S3 bucket or accept the default retention periods.
-
You can optionally enable encryption for AWS Control Tower resources by using an AWS Key Management Service (AWS KMS) customer managed key. If you enable encryption, you are asked to specify the key name or Amazon Resource Name (ARN) of the customer managed key to be used.