Skip to main content

AWS Control Tower Architecture

Document Control​

FieldDetails
ProjectAWS Control Tower Landing Zone
Version1.0
AuthorAnmol Nagpal
Last updated2026-07-01

Summary​

AWS Control Tower is the governance layer for a secure, compliant, multi-account AWS landing zone. It uses AWS Organizations for account hierarchy, IAM Identity Center for access, AWS Service Catalog for Account Factory, CloudFormation StackSets for baseline rollout, CloudTrail and Config for auditability, and controls for policy enforcement.

This architecture is designed for centralized governance with decentralized workload ownership. Platform administrators own the landing zone, controls, identity model, and shared security services, while workload teams operate inside enrolled accounts that inherit the approved governance baseline.

Architecture Diagram​

AWS Control Tower Architecture

Landing Zone Structure​

LayerPurposeDesign Notes
Organization rootParent container for all OUs and accountsKeep only required organization-wide policies at root. Apply environment-specific controls at OU level where possible.
Management accountControl plane and payer accountHosts AWS Control Tower administration. Access should be tightly restricted and monitored.
Security OUCentral security and logging boundaryContains Log Archive and Audit accounts by default. These are shared accounts and should not host workloads.
Log Archive accountImmutable audit log destinationStores CloudTrail and Config delivery data. Restrict delete access, enable encryption, and retain according to compliance needs.
Audit accountSecurity review and delegated administrator accountUsed for cross-account audit roles and delegated admin services such as GuardDuty and Security Hub.
Shared Services OUPlatform-wide shared servicesOptional but recommended for DNS, networking, CI/CD, observability, backup, and artifact services.
Workload OUsBusiness or environment workload isolationCommon examples: Development, Test, Staging, Production, Data, Security Tools.
Sandbox OUExperimentationOptional OU for short-lived experiments with budget controls and limited privileges.

Core Control Plane Flow​

  1. AWS Control Tower is configured from the management account.
  2. The landing zone setup creates or registers the required organization structure, shared accounts, IAM Identity Center configuration, and mandatory controls.
  3. Account Factory provisions accounts using AWS Service Catalog and AWS Organizations.
  4. AWS Control Tower assumes AWSControlTowerExecution in enrolled accounts to apply baselines and controls.
  5. AWS CloudFormation StackSets deploy AWS Control Tower managed resources across accounts and Regions.
  6. CloudTrail and Config record governance events and configuration state.
  7. EventBridge receives lifecycle events that can trigger post-provisioning automation.

Account Vending Flow​

StepServiceDescription
1Request channelAccount request is submitted through Account Factory, automation, or an approved platform workflow.
2AWS Service CatalogAccount Factory standardizes required account parameters and account product lifecycle.
3AWS OrganizationsAWS account is created or enrolled and placed in the target OU.
4IAMAWSControlTowerExecution enables Control Tower to baseline and manage the account.
5AWS Control TowerMandatory controls, baselines, logging, and audit roles are applied.
6CloudFormation StackSetsRequired baseline resources are deployed per account and Region.
7EventBridgeSuccessful lifecycle events trigger optional automation such as security service enrollment, baseline networking, and notifications.

Governance and Controls​

AWS Control Tower controls apply at the OU level and affect accounts inside the OU. The management account is intentionally exempt from controls that could otherwise make the management account unusable; actions in that account should still be tracked through audit logs.

Control TypePurposeExample Use
PreventivePrevent disallowed actions before they happen, commonly through service control policies.Deny disabling centralized logging in governed accounts.
DetectiveDetect resources or configurations that violate policy, commonly through AWS Config rules.Detect public S3 bucket access or unencrypted resources.
ProactiveCheck resources before provisioning when supported.Validate CloudFormation resources against policy before deployment.
GuidanceExpected Use
MandatoryEnabled as part of the landing zone baseline.
Strongly recommendedEnable unless a documented exception exists.
ElectiveEnable based on workload, compliance, and organizational requirements.

Security Architecture​

Security CapabilityAccount/LocationImplementation Notes
Identity federationIAM Identity CenterUse permission sets mapped to groups. Integrate with an external IdP when required by client policy.
Break-glass accessManagement and security accountsMaintain tightly controlled emergency access with monitoring and periodic testing.
Central loggingLog Archive accountCentralize CloudTrail and Config logs in encrypted S3 buckets with restricted access.
Security auditAudit accountUse cross-account audit roles and delegated admin capabilities for visibility.
Threat detectionAudit or security tooling accountDelegate GuardDuty administration and aggregate findings across accounts and Regions.
Security postureAudit or security tooling accountDelegate Security Hub CSPM and aggregate standards/finding status.
EncryptionS3, KMS, service integrationsUse customer managed keys when required by policy; rotate keys where supported.
Network segmentationWorkload accounts and networking accountsUse separate VPCs per environment and centralized connectivity patterns as needed.

Observability and Audit Flow​

SourceDestinationPurpose
AWS CloudTrail organization activityLog Archive accountAudit account and API activity across the organization.
AWS Control Tower lifecycle eventsCloudTrail, EventBridge, CloudWatch EventsTrack completion or failure of landing zone, account, OU, baseline, and control operations.
AWS Config recorders and rulesAccount-local Config plus aggregationDetect resource configuration drift and detective control compliance.
GuardDuty findingsDelegated administrator accountCentral threat detection and investigation workflow.
Security Hub findingsDelegated administrator accountSecurity posture management and standards compliance reporting.

Extension Architecture​

Extension AreaRecommended Pattern
Account customizationTrigger automation from Control Tower lifecycle events after account enrollment succeeds.
Baseline infrastructureUse Terraform, CloudFormation StackSets, or Account Factory customizations for customer-owned resources.
Security servicesUse delegated administrator accounts instead of configuring every account manually.
NotificationsSend EventBridge events to SNS, Lambda, or ticketing integrations.
Network baselineDeploy account VPCs, Transit Gateway attachments, DNS, and routing through controlled infrastructure pipelines.
Policy-as-codeValidate Terraform, CloudFormation, and IAM changes in CI before applying to governed accounts.

Failure and Drift Considerations​

ScenarioImpactResponse
Manual edit to AWS Control Tower managed resourcesLanding zone or control state may become unknown or drifted.Reconcile through AWS Control Tower supported update/reset workflows.
Account created outside Account FactoryAccount may be unmanaged or missing baselines.Enroll the account or move it to an unmanaged OU with documented exception.
Failed account provisioningAccount may exist but not be fully baselined.Review lifecycle events and Account Factory product status; retry supported update/enrollment workflow.
Control enablement failureOU may not have expected governance coverage.Review Control Tower activities, CloudFormation StackSets, Config rules, and service-linked roles.
Missing EventBridge automation triggerPost-provisioning tasks may not run.Ensure CloudTrail is active and EventBridge rules target the correct event names.

Architecture Decisions​

DecisionRationale
Use Control Tower as the landing zone authorityProvides prescriptive multi-account governance and reduces bespoke account setup.
Keep workloads out of management, Log Archive, and Audit accountsReduces blast radius and protects control plane, logging, and security review functions.
Apply controls by OUAligns governance with environment risk and account purpose.
Use Account Factory for account vendingStandardizes account creation, enrollment, and baseline application.
Use lifecycle events for automationAvoids racing against account creation and triggers automation after Control Tower actions complete.
Delegate security servicesCentralizes visibility while keeping member accounts manageable.

References​