Skip to main content
  1. Projects/
  2. AWS DevOps Pro Certification/
  3. 2: Configuration Mgmt / Infrastructure as Code/
  4. 3: Containers and More/

5: AWS Control Tower

·1 min

What’s Control Tower?

  • Set up and govern multi-account environments
  • It’s an extension of “AWS Organizations”
  • Good for security and governance

Why use it?

  • Deploying apps to multiple accounts is a big paradigm in AWS
  • Provides additional control / presets

How’s it work?

  • Creates a multi-account baseline called a landing zone:
  • LZ creates organizational units (OU’s) and accounts for us
    • Security best practices are baked in already


  • If you don’t have an org, control tower will make one for you
  • What’s a landing zone? Look above.
  • Two types of guardrails:
    • Preventative
    • Detective