Section 5: Organisations & Control Tower Flashcards
What is AWS Organizations
AWS Organizations allows to to have one organisation for many AWS accounts
Allows to have 1 bill and allows goverence across all accounts (centrally manage all accounts)
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_introduction.html
What is a Service Control Policy?
A Service Control Policy is a JSON file which controls permissions. This can be applied to orgnisations, stating for example what resources they have access to using. This file is added/uploaded to AWS.
What is AWS Control Tower?
AWS Control Tower sits above AWS Orgnisations. It create a well-architected multi-account based on best practices (known as a landing zone). Guardrails are used for governance and compliance.
What are the two feature sets AWS Organizations is available in?
The two feature sets AWS Organizations are:
- Consolidated billing
- All features
https://digitalcloud.training/aws-organizations/