Soru

Zorluk: Çok zorMulti-Account Governance and Organizational Structure

An enterprise is establishing a secure, automated multi-account landing zone using AWS Organizations and AWS Control Tower. The solutions architect needs to design a governance structure that automatically deploys custom Service Control Policies (SCPs) and baseline resources to all new accounts, while securing federated access for developers.

Arrange the following steps in the correct chronological sequence to implement this governance architecture from scratch according to AWS best practices.

  1. 1Launch AWS Control Tower in the Organizations management account to establish the landing zone and automatically provision the security and logging accounts.
  2. 2Create additional custom Organizational Units (OUs) under the organization root to define the logical boundaries for workloads (e.g., Workloads-Prod, Workloads-Dev).
  3. 3Deploy the Customizations for AWS Control Tower (CfCT) pipeline to manage custom CloudFormation templates and Service Control Policies (SCPs).
  4. 4Provision new member accounts or enroll existing accounts into their designated workload OUs using the AWS Control Tower Account Factory.
  5. 5Configure AWS IAM Identity Center permission sets and assign them to federated groups for the newly created member accounts.

Cevap

The correct chronological sequence is: first launch AWS Control Tower to set up the landing zone; second, define the workload Organizational Units; third, deploy the Customizations for AWS Control Tower (CfCT) pipeline; fourth, provision member accounts via the Account Factory; and fifth, configure and map AWS IAM Identity Center permissions to the newly created accounts.
The correct sequence starts with launching AWS Control Tower to initialize the landing zone and establish the core logging and security accounts. Next, custom OUs must be created in AWS Organizations to house future workloads. Then, the CfCT framework is deployed so it is active and ready to handle account lifecycle events. Afterwards, accounts are provisioned or enrolled via Account Factory, automatically receiving CfCT customizations. Finally, IAM Identity Center is configured to grant users federated access to the newly active accounts.

Adım Adım Çözüm

1
Initialize AWS Control Tower
The AWS Organizations management structure is configured, and the core Log Archive and Audit accounts are created.
This establishes the control plane and foundational account structure required for all subsequent steps.
2
Create Custom Organizational Units (OUs)
A structured OU hierarchy is established to group workloads based on security and operational requirements.
Target OUs must exist before we can attach policies or enroll member accounts into them.
3
Deploy Customizations for AWS Control Tower (CfCT)
A pipeline is deployed in the management account that listens to Control Tower lifecycle events.
Deploying CfCT beforehand ensures that custom resources and guardrails are automatically deployed when new accounts are provisioned.
4
Provision/Enroll Accounts
Member accounts are successfully created under the correct OUs and automatically receive custom baselines via CfCT.
Account provisioning triggers lifecycle events, prompting the CfCT pipeline to configure the new accounts.
5
Assign Federated Access
Users can federate into the new accounts with appropriate roles and permission sets.
Access assignments require the target account IDs and OUs to be fully active and provisioned.

Anahtar Kavram

Establishing multi-account governance using AWS Organizations, AWS Control Tower, CfCT customization pipeline, and AWS IAM Identity Center.
Tahmini Süre:3m 0s
Bu soruyu puanla