AWS Control Tower Core Services
Document Control​
| Field | Details |
|---|---|
| Project | AWS Control Tower Landing Zone |
| Version | 1.0 |
| Author | Anmol Nagpal |
| Last updated | 2026-07-01 |
Summary​
AWS Control Tower is not a single isolated service; it coordinates multiple AWS management, governance, identity, security, and deployment services. Understanding these dependencies is important for operating the landing zone safely, troubleshooting account enrollment, and extending the platform through automation.
The following catalog describes each core service, its landing zone responsibility, and the operational notes that platform teams should follow.
Service Catalog​
| Service | Landing Zone Responsibility | Operational Notes |
|---|---|---|
| AWS Control Tower | Orchestrates landing zone setup, account enrollment, controls, baselines, drift visibility, and dashboard reporting. | Use supported Control Tower workflows for landing zone updates, OU registration, account enrollment, baseline resets, and control changes. |
| AWS Organizations | Provides the organization root, OUs, member accounts, service control policies, delegated administration, and consolidated governance. | Maintain a documented OU strategy. Avoid moving governed accounts without understanding baseline and control impact. |
| AWS IAM Identity Center | Provides central access portal, users/groups or external IdP integration, and permission set assignment. | Prefer group-based access. Review privileged permission sets regularly. |
| AWS Service Catalog | Provides Account Factory as a standardized account vending product. | Treat Account Factory products as the approved path for account creation and updates. |
| AWS CloudFormation StackSets | Deploys AWS Control Tower managed resources across accounts and Regions. | Do not manually change Control Tower managed StackSets or stack instances. Investigate outdated or failed stack instances during drift review. |
| AWS CloudTrail | Records API activity, organization events, and AWS Control Tower lifecycle events. | Ensure organization trails remain active and centralized logs are retained in the Log Archive account. |
| AWS Config | Records resource configuration and supports detective control evaluation. | Ensure recorders and delivery channels remain healthy in governed accounts and Regions. |
| Amazon EventBridge | Receives lifecycle events that can trigger automation after Control Tower operations complete. | Build idempotent post-provisioning automation because retries and update events can occur. |
| Amazon CloudWatch | Supports metrics, logs, alarms, and event visibility for platform operations. | Use alarms for failed automation, Control Tower integration functions, and security service health. |
| Amazon S3 | Stores centralized logs, artifacts, and optional landing zone customization packages. | Enable encryption, versioning where appropriate, lifecycle policies, and strict bucket policies. |
| AWS KMS | Provides encryption keys for supported logs, buckets, and security services. | Use key policies that allow required AWS services while preventing broad administrative access. |
| AWS IAM | Provides service roles, cross-account roles, and execution roles. | Protect AWSControlTowerExecution and Control Tower service roles. Do not remove trust relationships required by Control Tower. |
| AWS Lambda | Common extension point for account vending and lifecycle event automation. | Keep functions idempotent, observable, least-privileged, and safe to rerun. |
| AWS Step Functions | Optional orchestration for multi-step landing zone automation. | Use for longer workflows such as account customization, security enrollment, and approvals. |
| Amazon SNS | Optional notification fanout for events, approvals, and alerts. | Use topic policies and subscriptions aligned to platform operations and incident response. |
| AWS Security Hub CSPM | Central security posture management and standards compliance aggregation. | Configure delegated administration and auto-enable for new accounts where supported by client requirements. |
| Amazon GuardDuty | Threat detection across AWS accounts and Regions. | Configure delegated administration and organization auto-enablement where required. |
| AWS Backup | Optional centralized backup policy and reporting service. | Apply backup policies based on workload criticality and compliance requirements. |
Account and OU Services​
| Capability | Primary Service | Supporting Services | Notes |
|---|---|---|---|
| OU hierarchy | AWS Organizations | AWS Control Tower | OUs define where controls and baselines apply. |
| Account creation | Account Factory | AWS Service Catalog, AWS Organizations | Use standard parameters for owner, email, OU, environment, and cost center. |
| Existing account enrollment | AWS Control Tower | IAM, AWS Organizations | Existing accounts must satisfy enrollment prerequisites, including required roles. |
| Account movement | AWS Control Tower / AWS Organizations | AWS Config, StackSets | Moving accounts between OUs changes governance scope. Validate controls before and after movement. |
| Account closure | AWS Organizations | AWS Control Tower, billing process | Follow client decommissioning, data retention, and billing closeout procedures. |
Identity and Access Services​
| Capability | Recommended Implementation |
|---|---|
| Human access | IAM Identity Center with group-based permission sets. |
| CI/CD access | OIDC federation into workload accounts with least-privilege IAM roles. |
| Emergency access | Break-glass role or user with strict MFA, alerting, and periodic access tests. |
| Cross-account audit | AWS Control Tower audit roles and delegated security tooling in the Audit account. |
| Management account access | Small administrator group, ticketed approval, logging, and session monitoring. |
Logging and Monitoring Services​
| Capability | Recommended Implementation |
|---|---|
| API audit logs | CloudTrail organization trail delivered to the Log Archive account. |
| Configuration history | AWS Config enabled for governed accounts and Regions. |
| Control compliance | AWS Control Tower dashboard, AWS Config rules, and Security Hub where integrated. |
| Lifecycle tracking | Control Tower lifecycle events in CloudTrail and EventBridge. |
| Security findings | GuardDuty and Security Hub delegated administrator accounts. |
| Operations alerts | CloudWatch alarms, EventBridge rules, and SNS notifications. |
Controls and Baselines​
| Item | Description |
|---|---|
| Baseline | The required resource and configuration setup that AWS Control Tower applies to OUs and enrolled accounts. |
| Mandatory controls | Controls applied by AWS Control Tower as part of the landing zone foundation. |
| Strongly recommended controls | Controls that should normally be enabled unless a documented exception exists. |
| Elective controls | Controls selected based on workload type, compliance scope, and risk appetite. |
| Preventive controls | Controls that prevent disallowed actions, commonly implemented with service control policies. |
| Detective controls | Controls that detect non-compliant resource configurations, commonly implemented with AWS Config. |
| Proactive controls | Controls that evaluate supported resources before provisioning. |
Lifecycle Events​
AWS Control Tower emits lifecycle events when state-changing operations complete or fail. These events support audit review and automation.
| Event Area | Common Event Names |
|---|---|
| Account operations | CreateManagedAccount, UpdateManagedAccount |
| Landing zone operations | SetupLandingZone, UpdateLandingZone |
| OU operations | RegisterOrganizationalUnit, DeregisterOrganizationalUnit, PrecheckOrganizationalUnit |
| Baseline operations | EnableBaseline, ResetEnabledBaseline, UpdateEnabledBaseline, DisableBaseline |
| Control operations | EnableControl, ResetEnabledControl, UpdateEnabledControl, DisableControl |
Automation should check event result status and account/OU identifiers before acting. When account creation is retried after partial provisioning, AWS Control Tower may emit an update event instead of a create event, so automation should handle both create and update paths.
Operating Checklist​
| Check | Frequency | Owner |
|---|---|---|
| Review Control Tower dashboard for drift and noncompliance. | Weekly | Platform team |
| Review failed CloudFormation StackSet instances. | Weekly or after landing zone updates | Platform team |
| Review account inventory and OU placement. | Monthly | Platform team |
| Review IAM Identity Center users, groups, and permission sets. | Monthly | Security/platform team |
| Review Security Hub and GuardDuty delegated admin health. | Weekly | Security team |
| Review lifecycle automation failures. | Daily or via alert | Platform team |
| Review exception register for expiring exceptions. | Monthly | Governance owner |
| Test break-glass access. | Quarterly | Security/platform team |
References​
- AWS Control Tower - Integrated services
- AWS Control Tower - What is AWS Control Tower?
- AWS Control Tower - How AWS Control Tower works
- AWS Control Tower - Provision and manage accounts with Account Factory
- AWS Control Tower - How AWS Control Tower works with roles
- AWS Control Tower - Lifecycle events
- AWS Control Tower - About controls