AWS Organizations
AWS Organizations is the service to create and manage several AWS accounts as one organization. Using separate accounts for environments (dev, pro), teams or workloads limits the impact of mistakes and attacks, and Organizations makes that manageable.
Key concepts #
- Management account and member accounts. New accounts can be created through the API, with an automatic IAM role to administer them from the management account.
- Organizational units (OUs): a tree of groups of accounts, to apply policies to many accounts at once.
- Service control policies (SCPs): guardrails that define the maximum permissions that the IAM users and roles of an account can have. For example: deny leaving the organization, deny disabling CloudTrail or deny using Regions that are not allowed. SCPs do not grant permissions, they limit them.
- Consolidated billing: one bill for all the accounts, with volume discounts and shared Savings Plans and Reserved Instances.
- Other policy types: tag policies, backup policies and AI services opt-out policies.
- Integrated services: organization-wide CloudTrail trails, IAM Identity Center for single sign-on, AWS Config, Security Hub, RAM (resource sharing) and more.
- AWS Control Tower builds a landing zone with best-practice guardrails on top of Organizations.
- Best practice: do not run workloads in the management account, and protect the root user of every account with MFA.
Pricing #
AWS Organizations has no additional charge.
With Terraform #
The resources are aws_organizations_organization, aws_organizations_organizational_unit, aws_organizations_account and aws_organizations_policy, with aws_organizations_policy_attachment.
See tutorials: