Slide 1

Slide 1 text

Getting Started with AWS Landing Zones The key to manage and govern AWS accounts at scale Will Chalmers (he/him) Solutions Architect

Slide 2

Slide 2 text

• The path to multiple AWS accounts • Where does a landing zone fit in? • AWS Multi-Account Strategy • Control Tower & Organizations Agenda

Slide 3

Slide 3 text

The path to multiple accounts

Slide 4

Slide 4 text

No content

Slide 5

Slide 5 text

Security / Resource Boundary API Limits / throttling Billing Separation

Slide 6

Slide 6 text

Where does a Landing Zone fit in?

Slide 7

Slide 7 text

Multi Account Structure

Slide 8

Slide 8 text

You Need … Orchestration Framework

Slide 9

Slide 9 text

You need a ‘Landing Zone’ • A configured, secure, scalable, multi-account AWS environment based on AWS Frameworks and best practices. • A starting point for new clients/projects/migrations/development & experimentation • An environment that allows for iteration and expansion over time

Slide 10

Slide 10 text

A well-architected Landing Zone

Slide 11

Slide 11 text

Introducing AWS Control Tower A self-service solutions to automate the setup of AWS multi-account environments

Slide 12

Slide 12 text

Benefits

Slide 13

Slide 13 text

AWS Organizations Provides tools to centrally govern and manage AWS Accounts • Quickly scale by creating accounts and allocate resources • Customize environments by applying governance policies • Secure and audit environments • Manage costs and identify cost-saving measures

Slide 14

Slide 14 text

Benefits

Slide 15

Slide 15 text

Dashboard for oversight

Slide 16

Slide 16 text

Guardrail examples Guardrail Type Requirement Enable MFA for the Root User Detective Strongly Recommended Disallow public read access to S3 Detective Strongly Recommended Enable AWS Config in All Available Regions Preventive Mandatory Disallow Policy Changes to Log Archive Preventive Mandatory Integrate CloudTrail Events with CloudWatch Logs Preventive Mandatory Disallow Amazon S3 Buckets That Are Not Versioning Enabled Detective Elective Disallow Delete Actions on Amazon S3 Buckets Without MFA Detective Elective

Slide 17

Slide 17 text

Account Creation

Slide 18

Slide 18 text

Thank you! Q&A