Back to Templates

AWS Landing Zone with Control Tower

Created by Bolum Team
Updated: 4/8/2024
445
AWSMulti-AccountEnterprise

Set up a well-architected AWS multi-account environment.

This template implements AWS best practices for account structure, security guardrails, centralized logging, and identity management using Control Tower and Organizations.

What This Template Does

1
Sets up AWS Organizations structure
2
Configures Control Tower guardrails
3
Implements AWS SSO for centralized access
4
Creates shared services accounts
5
Sets up centralized CloudTrail and Config
6
Deploys Service Control Policies

How to Set It Up

1

Enable Control Tower

Set up AWS Control Tower in your management account.

2

Configure OUs

Create organizational units following our structure.

3

Deploy guardrails

Apply the SCPs and detective controls.

4

Set up SSO

Configure AWS SSO with your identity provider.

5

Vend accounts

Use Account Factory to create new workload accounts.

Tools Used

AWS Control TowerAWS OrganizationsAWS SSOCloudFormation

Ready to use this template?

Our team will help you customize and deploy it for your infrastructure.