CLOUD FOUNDATIONS
Getting to know the AWS Landing Zone
Build an organized multi-account AWS foundation, with access, governance and operational responsibilities considered before migration.
Start with a clear account structure
A landing zone is an organized, multi-account AWS environment for starting and growing cloud workloads. Separating accounts helps establish clear boundaries between workloads and responsibilities.
Before migrating, agree how to organize production, development and shared services, and identify who owns each environment.
Build identity and governance into the foundation
AWS Control Tower helps set up and govern a landing zone, coordinating services such as AWS Organizations and IAM Identity Center. A customized approach still needs clear decisions about accounts, access and operations.
Controls and logging support governance; they do not automatically satisfy every compliance requirement.
Prepare before the first workload
Set repeatable foundations before migration so teams start from consistent standards and understand their responsibilities.
- Assign ownership for access and log review.
- Plan networking and connections between environments.
- Define how accounts and new workloads are provisioned.
- Document decisions and revisit them as the organization changes.