# AWS Organizations

> AWS Organizations lets you manage many AWS accounts centrally: organizational units, consolidated billing and service control policies to set guardrails.

- Source: https://www.itwonderlab.com/aws-organizations/
- Published: 2026-10-05
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**AWS Organizations** is the service to create and manage **several AWS accounts** as one organization. Using separate accounts for environments (`dev`, `pro`), teams or workloads limits the impact of mistakes and attacks, and Organizations makes that manageable.

### Key concepts

- **Management account** and **member accounts**. New accounts can be created through the API, with an automatic [IAM](https://www.itwonderlab.com/aws-iam/) role to administer them from the management account.
- **Organizational units (OUs)**: a tree of groups of accounts, to apply policies to many accounts at once.
- **Service control policies (SCPs)**: guardrails that define the **maximum permissions** that the IAM users and roles of an account can have. For example: deny leaving the organization, deny disabling [CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/) or deny using Regions that are not allowed. SCPs do not grant permissions, they limit them.
- **Consolidated billing**: one bill for all the accounts, with volume discounts and shared Savings Plans and Reserved Instances.
- Other policy types: tag policies, backup policies and AI services opt-out policies.
- **Integrated services**: organization-wide [CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/) trails, IAM Identity Center for single sign-on, AWS Config, Security Hub, RAM (resource sharing) and more.
- **AWS Control Tower** builds a landing zone with best-practice guardrails on top of Organizations.
- Best practice: do not run workloads in the management account, and protect the root user of every account with MFA.

### Pricing

AWS Organizations has **no additional charge**.

### With Terraform

The resources are `aws_organizations_organization`, `aws_organizations_organizational_unit`, `aws_organizations_account` and `aws_organizations_policy`, with `aws_organizations_policy_attachment`.

See tutorials:

-   [Create an AWS Account for Demos](https://www.itwonderlab.com/create-an-aws-account-for-demos/)
-   [Create an AWS IAM User for Demos](https://www.itwonderlab.com/create-an-aws-iam-user-for-demos/)
