AWS Control Tower makes multi-account AWS management easy
Rating: 9 out of 10
IncentivizedUse Cases and Deployment Scope
We have multiple companies along with multiple clients that require separate AWS accounts. With AWS Control Tower it makes it simple and easy to have a central point to monitor and control all the AWS accounts.
Pros
- Guardrails make securing accounts easy and quick.
- AWS SSO allows us a central point for controlling users and groups across each account.
- Centralized logging serves as a single point to monitor each environment.
- Landing zones allow us to apply templates for each account and customize each one from a central point as well.
Cons
- The AWS SSO GUI is not very intuitive and determining how to apply policies to users without creating redundant logins has been a challenge.
- The default guardrails do not fully encompass all the security checks that we needed.
- There does not appear to be any way to control roles at the IAM level from the control tower account through the GUI.
- Some features on AWS accounts still require logging into the individual account with the root user and cannot be done from AWS Control Tower.
Likelihood to Recommend
If you have more than 3 AWS accounts or strict security requirements (e.g PCI, SOC II) Control Tower is a must. If you only have 1-2 accounts and few users the added complexity of the control tower is likely not worth the time.