Skip to main content

AWS Control Tower Core Services

Document Control​

FieldDetails
ProjectAWS Control Tower Landing Zone
Version1.0
AuthorAnmol Nagpal
Last updated2026-07-01

Summary​

AWS Control Tower is not a single isolated service; it coordinates multiple AWS management, governance, identity, security, and deployment services. Understanding these dependencies is important for operating the landing zone safely, troubleshooting account enrollment, and extending the platform through automation.

The following catalog describes each core service, its landing zone responsibility, and the operational notes that platform teams should follow.

Service Catalog​

ServiceLanding Zone ResponsibilityOperational Notes
AWS Control TowerOrchestrates landing zone setup, account enrollment, controls, baselines, drift visibility, and dashboard reporting.Use supported Control Tower workflows for landing zone updates, OU registration, account enrollment, baseline resets, and control changes.
AWS OrganizationsProvides the organization root, OUs, member accounts, service control policies, delegated administration, and consolidated governance.Maintain a documented OU strategy. Avoid moving governed accounts without understanding baseline and control impact.
AWS IAM Identity CenterProvides central access portal, users/groups or external IdP integration, and permission set assignment.Prefer group-based access. Review privileged permission sets regularly.
AWS Service CatalogProvides Account Factory as a standardized account vending product.Treat Account Factory products as the approved path for account creation and updates.
AWS CloudFormation StackSetsDeploys AWS Control Tower managed resources across accounts and Regions.Do not manually change Control Tower managed StackSets or stack instances. Investigate outdated or failed stack instances during drift review.
AWS CloudTrailRecords API activity, organization events, and AWS Control Tower lifecycle events.Ensure organization trails remain active and centralized logs are retained in the Log Archive account.
AWS ConfigRecords resource configuration and supports detective control evaluation.Ensure recorders and delivery channels remain healthy in governed accounts and Regions.
Amazon EventBridgeReceives lifecycle events that can trigger automation after Control Tower operations complete.Build idempotent post-provisioning automation because retries and update events can occur.
Amazon CloudWatchSupports metrics, logs, alarms, and event visibility for platform operations.Use alarms for failed automation, Control Tower integration functions, and security service health.
Amazon S3Stores centralized logs, artifacts, and optional landing zone customization packages.Enable encryption, versioning where appropriate, lifecycle policies, and strict bucket policies.
AWS KMSProvides encryption keys for supported logs, buckets, and security services.Use key policies that allow required AWS services while preventing broad administrative access.
AWS IAMProvides service roles, cross-account roles, and execution roles.Protect AWSControlTowerExecution and Control Tower service roles. Do not remove trust relationships required by Control Tower.
AWS LambdaCommon extension point for account vending and lifecycle event automation.Keep functions idempotent, observable, least-privileged, and safe to rerun.
AWS Step FunctionsOptional orchestration for multi-step landing zone automation.Use for longer workflows such as account customization, security enrollment, and approvals.
Amazon SNSOptional notification fanout for events, approvals, and alerts.Use topic policies and subscriptions aligned to platform operations and incident response.
AWS Security Hub CSPMCentral security posture management and standards compliance aggregation.Configure delegated administration and auto-enable for new accounts where supported by client requirements.
Amazon GuardDutyThreat detection across AWS accounts and Regions.Configure delegated administration and organization auto-enablement where required.
AWS BackupOptional centralized backup policy and reporting service.Apply backup policies based on workload criticality and compliance requirements.

Account and OU Services​

CapabilityPrimary ServiceSupporting ServicesNotes
OU hierarchyAWS OrganizationsAWS Control TowerOUs define where controls and baselines apply.
Account creationAccount FactoryAWS Service Catalog, AWS OrganizationsUse standard parameters for owner, email, OU, environment, and cost center.
Existing account enrollmentAWS Control TowerIAM, AWS OrganizationsExisting accounts must satisfy enrollment prerequisites, including required roles.
Account movementAWS Control Tower / AWS OrganizationsAWS Config, StackSetsMoving accounts between OUs changes governance scope. Validate controls before and after movement.
Account closureAWS OrganizationsAWS Control Tower, billing processFollow client decommissioning, data retention, and billing closeout procedures.

Identity and Access Services​

CapabilityRecommended Implementation
Human accessIAM Identity Center with group-based permission sets.
CI/CD accessOIDC federation into workload accounts with least-privilege IAM roles.
Emergency accessBreak-glass role or user with strict MFA, alerting, and periodic access tests.
Cross-account auditAWS Control Tower audit roles and delegated security tooling in the Audit account.
Management account accessSmall administrator group, ticketed approval, logging, and session monitoring.

Logging and Monitoring Services​

CapabilityRecommended Implementation
API audit logsCloudTrail organization trail delivered to the Log Archive account.
Configuration historyAWS Config enabled for governed accounts and Regions.
Control complianceAWS Control Tower dashboard, AWS Config rules, and Security Hub where integrated.
Lifecycle trackingControl Tower lifecycle events in CloudTrail and EventBridge.
Security findingsGuardDuty and Security Hub delegated administrator accounts.
Operations alertsCloudWatch alarms, EventBridge rules, and SNS notifications.

Controls and Baselines​

ItemDescription
BaselineThe required resource and configuration setup that AWS Control Tower applies to OUs and enrolled accounts.
Mandatory controlsControls applied by AWS Control Tower as part of the landing zone foundation.
Strongly recommended controlsControls that should normally be enabled unless a documented exception exists.
Elective controlsControls selected based on workload type, compliance scope, and risk appetite.
Preventive controlsControls that prevent disallowed actions, commonly implemented with service control policies.
Detective controlsControls that detect non-compliant resource configurations, commonly implemented with AWS Config.
Proactive controlsControls that evaluate supported resources before provisioning.

Lifecycle Events​

AWS Control Tower emits lifecycle events when state-changing operations complete or fail. These events support audit review and automation.

Event AreaCommon Event Names
Account operationsCreateManagedAccount, UpdateManagedAccount
Landing zone operationsSetupLandingZone, UpdateLandingZone
OU operationsRegisterOrganizationalUnit, DeregisterOrganizationalUnit, PrecheckOrganizationalUnit
Baseline operationsEnableBaseline, ResetEnabledBaseline, UpdateEnabledBaseline, DisableBaseline
Control operationsEnableControl, ResetEnabledControl, UpdateEnabledControl, DisableControl

Automation should check event result status and account/OU identifiers before acting. When account creation is retried after partial provisioning, AWS Control Tower may emit an update event instead of a create event, so automation should handle both create and update paths.

Operating Checklist​

CheckFrequencyOwner
Review Control Tower dashboard for drift and noncompliance.WeeklyPlatform team
Review failed CloudFormation StackSet instances.Weekly or after landing zone updatesPlatform team
Review account inventory and OU placement.MonthlyPlatform team
Review IAM Identity Center users, groups, and permission sets.MonthlySecurity/platform team
Review Security Hub and GuardDuty delegated admin health.WeeklySecurity team
Review lifecycle automation failures.Daily or via alertPlatform team
Review exception register for expiring exceptions.MonthlyGovernance owner
Test break-glass access.QuarterlySecurity/platform team

References​