{"id":14775,"date":"2023-07-25T12:21:43","date_gmt":"2023-07-25T06:51:43","guid":{"rendered":"https:\/\/opstree.com\/blog\/\/?p=14775"},"modified":"2025-08-14T22:46:30","modified_gmt":"2025-08-14T17:16:30","slug":"multi-account-management-using-aws-control-tower","status":"publish","type":"post","link":"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/","title":{"rendered":"Multi-Account Management using AWS Control Tower"},"content":{"rendered":"\r\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">When an organization grows rapidly with time then the complexity of their cloud infrastructure, security concerns, and the need for better resource management also grows. Then there is a need for a more efficient and secure way to manage the workloads. To overcome these problems we can use multiple aws accounts in our aws environment. Some use cases where we can segregate AWS accounts are as follows:<!--more--><\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">We may have a dedicated production account that will protect the organization&#8217;s valuable data and minimize the risk of unauthorized access.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">There may be a separate development and testing account that allowed their teams to work without impacting the stability of the production systems.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Similarly, we may have a separate AWS account dedicated to replicating critical data, to ensure business continuity in the face of unforeseen events.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">In this way, if we use different AWS accounts then our infrastructure becomes more secure with a reduced blast radius. Resource management become easy, with better cost control and optimized resource allocation.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">In this blog post, we will explore why we need an <a href=\"https:\/\/opstree.com\/blog\/2024\/01\/02\/architecting-success-best-practices-for-implementing-aws-control-tower\/\">AWS control tower<\/a> for managing multiple AWS accounts, how we can set up AWS Control Tower, and how it can be leveraged to efficiently manage and govern multiple accounts using an account factory, organization units, guardrails, and logging and monitoring.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">Why do we need AWS Control Tower?<\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">We have multiple aws accounts in our organization and managing these AWS accounts can become more complex and time-consuming without a centralized management solution. Multiple AWS accounts also require additional administrative effort and resources. Some tasks such as managing user access and permissions across accounts, secure access across accounts, limited resource sharing, tracking, and managing costs and billing need to be performed separately for each account which leads to increased complexity and administrative overhead.<\/p>\r\n\r\n\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">To overcome these challenges we can use AWS Control Tower which offers a platform to establish and maintain a well-structured multi-account environment. This service offers centralized management, automated account provisioning, account grouping, consolidated billing, and enhanced governance capabilities to streamline the management of multiple <a href=\"https:\/\/opstree.com\/blog\/2024\/09\/10\/sharing-aws-encrypted-rds-snapshot-between-two-accounts\/\">AWS accounts<\/a>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Set up AWS Control Tower<\/strong><\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">First of all, we need to set up aws control tower so log in to the AWS Management Console of the AWS Account where you plan to deploy the AWS Control Tower. This account will be referred to as the Management account. Set up the AWS control tower by configuring and launching your landing zones on your Management account.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-14780\" style=\"width: 629px; height: 350px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-4.png?w=1024\" alt=\"\" width=\"629\" height=\"350\" \/><\/figure>\r\n\r\n\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Step 1: <strong>Review Pricing and select Regions<\/strong><\/h3>\r\n\r\n\r\n\r\n<p>On this page, we can see the services which are used with an AWS control tower and for those services, we need to pay based on our usage.<\/p>\r\n\r\n\r\n\r\n<p>Now under Home Region, select your home Region, this will be the default region where the resources of your shared accounts will be provisioned.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Under the region deny setting, choose &#8220;Enabled&#8221; if you want to deny access to other regions and if you choose &#8220;Not Enabled&#8221; then aws control tower remove the guardrail on all registered OU that will allow you to deploy resources in regions outside of AWS control tower availability. By default, the setting for this control is &#8220;Not Enabled&#8221;.<\/p>\r\n<p>You can check more info about <a href=\"https:\/\/opstree.com\/aws-consulting-services\/\"><strong>AWS Consulting Services<\/strong><\/a>.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Step 2: <strong>Configure Organizational Units<\/strong><\/h3>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Under this step, we have the Foundational OU that is initially named the Security OU, we can change it or leave it as it is.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Under Additional OU we can also create a new OU that can be used for development projects. If you already have an existing OU in AWS Organizations, you may see the option to skip setting up an Additional OU in AWS Control Tower.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14783\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-5.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Step 3: <strong>Configure Shared accounts<\/strong><\/h3>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Now we need to provide 2 AWS accounts one is for log archiving and the second for audit. We can create new accounts or can use existing accounts for this purpose. If you choose to create new shared accounts for yourself, the email addresses must not already have associated with other AWS accounts.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14785\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-6.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\">Step 4: <strong>Additional Configuration<\/strong><\/h3>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Under this step, you can select whether AWS Control Tower sets up AWS account access with <a href=\"https:\/\/opstree.com\/blog\/2023\/10\/10\/exploring-the-power-of-iam-roles-anywhere\/\">AWS Identity and Access Management (IAM)<\/a>, or whether to self-manage AWS account access\u2014either with AWS IAM Identity Center users, roles, and permissions that you can set up and customize on your own.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">By default, <a href=\"https:\/\/aws.amazon.com\/controltower\/\" target=\"_blank\" rel=\"noopener\"><strong>AWS Control Tower sets up AWS IAM Identity Center<\/strong><\/a> for your landing zone.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">You can choose &#8220;Enabled&#8221; or &#8220;Not Enabled&#8221; in AWS Cloudtrail Configuration. By default, it&#8217;s &#8220;Enabled&#8221;.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">You can also customize the log retention policy under Log Configuration for <a href=\"https:\/\/opstree.com\/blog\/2024\/11\/05\/amazon-s3-security-essentials-protect-your-data-with-these-key-practices\/\">Amazon S3<\/a>. By default, it&#8217;s one year for standard account logging and 10 years for access logging.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">You can also click on the checkbox to enable and customize the encryption setting under KMS Encryption. By default, this box is unchecked.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14789\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-7.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14790\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-8.png?w=893\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h3 class=\"wp-block-heading\"><strong>Step 5: Review and setup the Landing Zone<\/strong><\/h3>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Now take a review of all the configurations, acknowledge, and click on Set up a landing zone. It will take about 30 minutes to set up all of the resources in your landing zone.<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Once the landing zone is created, we can see the dashboard with all the details, such as OU, shared accounts, and controls.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14792\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-9.png?w=672\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<p>&nbsp;<\/p>\r\n<p><strong>[ Also Read: <a href=\"https:\/\/opstree.com\/blog\/2025\/05\/28\/aws-for-beginners-what-is-it-how-it-works-and-key-benefits\/\">What is Amazon Web Service (AWS)?<\/a> ]<\/strong><\/p>\r\n<h2 class=\"wp-block-heading\">Account Creation<\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Once AWS Control Tower is set up, you can create, update, unmanaged, close, and move member accounts from one organizational unit to another using AWS Control Tower&#8217;s account factory. The account factory allows you to provision new AWS accounts. These accounts will automatically inherit all the policies defined by the management account.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14793\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-10.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Account grouping<\/strong><\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">AWS Control Tower allows you to group accounts into organizational units (OUs) based on your organization&#8217;s structure or requirements. OUs work as a container for AWS accounts that allows you to apply different policies and guardrails to specific groups of accounts. You can create, delete and register OUs in the organization panel of the AWS control tower.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14795\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-11.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">If you are deploying AWS Control Tower into an existing organization, then you may also register existing organizational units and the accounts they hold.<\/p>\r\n<p>Are you looking <a href=\"https:\/\/opstree.com\/aws-partner\/\">Accelerating AI-Led Cloud Modernization<\/a>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Guardrails<\/strong><\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">AWS Control Tower provides a set of pre-defined guardrails that enforce best practices and compliance policies across all member accounts. By default, the Control tower applies <strong>20 preventive controls<\/strong> and <strong>3 detective controls<\/strong> that make sure of best practices. Guardrails are a set of predefined rules that help ensure governance and compliance. You can also customize these guardrails as per your organization&#8217;s specific requirements.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14797\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-12.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Centralize Billing and Cost Management<\/strong><\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">You can set up consolidated billing for all accounts in your AWS, which allows you to see a combined view of each account&#8217;s spending, making it easier to track and <a href=\"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/\">manage costs across multiple workloads<\/a>. Centralized billing allows you to audit all expenses from one dashboard.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14799\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-13.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Logging and Monitoring<\/strong><\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">When you set up your landing zone, a shared account log archive is created that is dedicated to collecting all logs including logs for all of your member accounts and management account centrally. These log files allow administrators and auditors to review actions and events that have occurred. Management account actions and events are viewable on the Activities page in the console while you can view member account actions and events in the log archive files.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14801\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-14.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<p>&nbsp;<\/p>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">AWS provides several tools like <a href=\"https:\/\/opstree.com\/blog\/2025\/07\/01\/logs-to-alerts-with-cloudwatch-filters\/\">Amazon CloudWatch<\/a> and <a href=\"https:\/\/opstree.com\/blog\/2021\/05\/04\/event-monitoring-using-aws-cloudtrail\/\">AWS CloudTrail for monitoring<\/a> your resources and activity in your landing zone. You can see the status of your controls in the AWS Control Tower console and the health of the accounts you provisioned in Account Factory also is monitored constantly. It also provides a dashboard where we can see the environment summary, enable controlled summary, non-compliant resources, registered organizational units, and enrolled AWS accounts.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" class=\"wp-image-14802\" style=\"width: 800px;\" src=\"https:\/\/opstree.com\/blog\/\/wp-content\/uploads\/2023\/07\/image-15.png?w=1024\" alt=\"\" width=\"800\" \/><\/figure>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\r\n\r\n\r\n\r\n<p class=\"has-text-align-justify\">Overall, AWS Control Tower is a valuable service that provides a comprehensive set of tools and best practices for securely managing multi-account <a href=\"https:\/\/opstree.com\/blog\/2024\/10\/11\/data-privacy-in-cloud-environments\/\">AWS environments<\/a>. It simplifies the process of creating and managing multiple AWS accounts. By leveraging AWS Control Tower, organizations can achieve consistent governance, enhanced security by applying security-related guardrails, simplified resource management, and improved cost optimization across AWS accounts.<\/p>\r\n\r\n\r\n\r\n\r\n<a class=\"wp-block-read-more\" href=\"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/\" target=\"_self\">https:\/\/docs.aws.amazon.com\/controltower\/latest\/userguide\/quick-start.html<span class=\"screen-reader-text\">: Multi-Account Management using AWS Control Tower<\/span><\/a>\r\n\r\n<a class=\"wp-block-read-more\" href=\"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/\" target=\"_self\">https:\/\/docs.aws.amazon.com\/audit-manager\/latest\/userguide\/controltower.html<span class=\"screen-reader-text\">: Multi-Account Management using AWS Control Tower<\/span><\/a>\r\n\r\n<a class=\"wp-block-read-more\" href=\"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/\" target=\"_self\">https:\/\/docs.aws.amazon.com\/controltower\/latest\/userguide\/logging-and-monitoring.html<span class=\"screen-reader-text\">: Multi-Account Management using AWS Control Tower<\/span><\/a>\r\n\r\n<a class=\"wp-block-read-more\" href=\"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/\" target=\"_self\">https:\/\/docs.aws.amazon.com\/controltower\/latest\/userguide\/account-factory.html<span class=\"screen-reader-text\">: Multi-Account Management using AWS Control Tower<\/span><\/a>\r\n\r\n\r\n\r\n\r\n\r\n\r\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\"><\/div>\r\n\r\n\r\n\r\n<ul class=\"wp-block-social-links aligncenter is-content-justification-center is-layout-flex wp-container-core-social-links-is-layout-1 wp-block-social-links-is-layout-flex\"><li class=\"wp-social-link wp-social-link-linkedin  wp-block-social-link\"><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/opstree-solutions\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M19.7,3H4.3C3.582,3,3,3.582,3,4.3v15.4C3,20.418,3.582,21,4.3,21h15.4c0.718,0,1.3-0.582,1.3-1.3V4.3 C21,3.582,20.418,3,19.7,3z M8.339,18.338H5.667v-8.59h2.672V18.338z M7.004,8.574c-0.857,0-1.549-0.694-1.549-1.548 c0-0.855,0.691-1.548,1.549-1.548c0.854,0,1.547,0.694,1.547,1.548C8.551,7.881,7.858,8.574,7.004,8.574z M18.339,18.338h-2.669 v-4.177c0-0.996-0.017-2.278-1.387-2.278c-1.389,0-1.601,1.086-1.601,2.206v4.249h-2.667v-8.59h2.559v1.174h0.037 c0.356-0.675,1.227-1.387,2.526-1.387c2.703,0,3.203,1.779,3.203,4.092V18.338z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">LinkedIn<\/span><\/a><\/li>\r\n\r\n<li class=\"wp-social-link wp-social-link-youtube  wp-block-social-link\"><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/channel\/UCeLma6SpNYH7jjYKSBNSexw\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M21.8,8.001c0,0-0.195-1.378-0.795-1.985c-0.76-0.797-1.613-0.801-2.004-0.847c-2.799-0.202-6.997-0.202-6.997-0.202 h-0.009c0,0-4.198,0-6.997,0.202C4.608,5.216,3.756,5.22,2.995,6.016C2.395,6.623,2.2,8.001,2.2,8.001S2,9.62,2,11.238v1.517 c0,1.618,0.2,3.237,0.2,3.237s0.195,1.378,0.795,1.985c0.761,0.797,1.76,0.771,2.205,0.855c1.6,0.153,6.8,0.201,6.8,0.201 s4.203-0.006,7.001-0.209c0.391-0.047,1.243-0.051,2.004-0.847c0.6-0.607,0.795-1.985,0.795-1.985s0.2-1.618,0.2-3.237v-1.517 C22,9.62,21.8,8.001,21.8,8.001z M9.935,14.594l-0.001-5.62l5.404,2.82L9.935,14.594z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">YouTube<\/span><\/a><\/li>\r\n\r\n<li class=\"wp-social-link wp-social-link-github  wp-block-social-link\"><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/OpsTree\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M12,2C6.477,2,2,6.477,2,12c0,4.419,2.865,8.166,6.839,9.489c0.5,0.09,0.682-0.218,0.682-0.484 c0-0.236-0.009-0.866-0.014-1.699c-2.782,0.602-3.369-1.34-3.369-1.34c-0.455-1.157-1.11-1.465-1.11-1.465 c-0.909-0.62,0.069-0.608,0.069-0.608c1.004,0.071,1.532,1.03,1.532,1.03c0.891,1.529,2.341,1.089,2.91,0.833 c0.091-0.647,0.349-1.086,0.635-1.337c-2.22-0.251-4.555-1.111-4.555-4.943c0-1.091,0.39-1.984,1.03-2.682 C6.546,8.54,6.202,7.524,6.746,6.148c0,0,0.84-0.269,2.75,1.025C10.295,6.95,11.15,6.84,12,6.836 c0.85,0.004,1.705,0.114,2.504,0.336c1.909-1.294,2.748-1.025,2.748-1.025c0.546,1.376,0.202,2.394,0.1,2.646 c0.64,0.699,1.026,1.591,1.026,2.682c0,3.841-2.337,4.687-4.565,4.935c0.359,0.307,0.679,0.917,0.679,1.852 c0,1.335-0.012,2.415-0.012,2.741c0,0.269,0.18,0.579,0.688,0.481C19.138,20.161,22,16.416,22,12C22,6.477,17.523,2,12,2z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">GitHub<\/span><\/a><\/li>\r\n\r\n<li class=\"wp-social-link wp-social-link-facebook  wp-block-social-link\"><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/www.facebook.com\/opstree\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M12 2C6.5 2 2 6.5 2 12c0 5 3.7 9.1 8.4 9.9v-7H7.9V12h2.5V9.8c0-2.5 1.5-3.9 3.8-3.9 1.1 0 2.2.2 2.2.2v2.5h-1.3c-1.2 0-1.6.8-1.6 1.6V12h2.8l-.4 2.9h-2.3v7C18.3 21.1 22 17 22 12c0-5.5-4.5-10-10-10z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">Facebook<\/span><\/a><\/li>\r\n\r\n<li class=\"wp-social-link wp-social-link-medium  wp-block-social-link\"><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/medium.com\/buildpiper\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M20.962,7.257l-5.457,8.867l-3.923-6.375l3.126-5.08c0.112-0.182,0.319-0.286,0.527-0.286c0.05,0,0.1,0.008,0.149,0.02 c0.039,0.01,0.078,0.023,0.114,0.041l5.43,2.715l0.006,0.003c0.004,0.002,0.007,0.006,0.011,0.008 C20.971,7.191,20.98,7.227,20.962,7.257z M9.86,8.592v5.783l5.14,2.57L9.86,8.592z M15.772,17.331l4.231,2.115 C20.554,19.721,21,19.529,21,19.016V8.835L15.772,17.331z M8.968,7.178L3.665,4.527C3.569,4.479,3.478,4.456,3.395,4.456 C3.163,4.456,3,4.636,3,4.938v11.45c0,0.306,0.224,0.669,0.498,0.806l4.671,2.335c0.12,0.06,0.234,0.088,0.337,0.088 c0.29,0,0.494-0.225,0.494-0.602V7.231C9,7.208,8.988,7.188,8.968,7.178z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">Medium<\/span><\/a><\/li>\r\n\r\n<li class=\"wp-social-link wp-social-link-twitter  wp-block-social-link\"><a rel=\"noopener nofollow\" target=\"_blank\" href=\"https:\/\/twitter.com\/opstreedevops\" class=\"wp-block-social-link-anchor\"><svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\" focusable=\"false\"><path d=\"M22.23,5.924c-0.736,0.326-1.527,0.547-2.357,0.646c0.847-0.508,1.498-1.312,1.804-2.27 c-0.793,0.47-1.671,0.812-2.606,0.996C18.324,4.498,17.257,4,16.077,4c-2.266,0-4.103,1.837-4.103,4.103 c0,0.322,0.036,0.635,0.106,0.935C8.67,8.867,5.647,7.234,3.623,4.751C3.27,5.357,3.067,6.062,3.067,6.814 c0,1.424,0.724,2.679,1.825,3.415c-0.673-0.021-1.305-0.206-1.859-0.513c0,0.017,0,0.034,0,0.052c0,1.988,1.414,3.647,3.292,4.023 c-0.344,0.094-0.707,0.144-1.081,0.144c-0.264,0-0.521-0.026-0.772-0.074c0.522,1.63,2.038,2.816,3.833,2.85 c-1.404,1.1-3.174,1.756-5.096,1.756c-0.331,0-0.658-0.019-0.979-0.057c1.816,1.164,3.973,1.843,6.29,1.843 c7.547,0,11.675-6.252,11.675-11.675c0-0.178-0.004-0.355-0.012-0.531C20.985,7.47,21.68,6.747,22.23,5.924z\"><\/path><\/svg><span class=\"wp-block-social-link-label screen-reader-text\">Twitter<\/span><\/a><\/li><\/ul>\r\n","protected":false},"excerpt":{"rendered":"<p>Introduction When an organization grows rapidly with time then the complexity of their cloud infrastructure, security concerns, and the need for better resource management also grows. Then there is a need for a more efficient and secure way to manage the workloads. To overcome these problems we can use multiple aws accounts in our aws &hellip; <a href=\"https:\/\/opstree.com\/blog\/2023\/07\/25\/multi-account-management-using-aws-control-tower\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Multi-Account Management using AWS Control Tower&#8221;<\/span><\/a><\/p>\n","protected":false},"author":237746390,"featured_media":29508,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"[]","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[36349927],"tags":[768739294,725105243,768739308,676319247,4996032],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/opstree.com\/blog\/wp-content\/uploads\/2023\/07\/AWS-Control-Tower-.jpg","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pfDBOm-3Qj","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/posts\/14775"}],"collection":[{"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/users\/237746390"}],"replies":[{"embeddable":true,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/comments?post=14775"}],"version-history":[{"count":28,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/posts\/14775\/revisions"}],"predecessor-version":[{"id":29509,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/posts\/14775\/revisions\/29509"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/media\/29508"}],"wp:attachment":[{"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/media?parent=14775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/categories?post=14775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/opstree.com\/blog\/wp-json\/wp\/v2\/tags?post=14775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}