Scenario where you have to manage several accounts in your company being the Cloud Administrator.
AWS Organizations helps you centrally manage and govern your environment as you grow and scale your AWS resources.
Using AWS Organizations, you can create accounts and allocate resources, group accounts to organize your workflows.
Apply policies for governance using SCP(Service Control Policy)
Simplify billing by using a single payment method for all of your accounts(consolidated billing)
It consists of two entities:
- Management/Master account: The management account creates the organization.
- Member account: these are accounts which are invited by the management account.
Click to the AWS console
Login to you accounts with your IAM credentials
Click on the AWS Organization title indicate above
Click the Create Organization on the home page
After creating an organization, invitation can be send to member account either existing account or a new account
when you create a new account the role is automatically given, BUT adding an existing account requires to manually create the role
Grant OrganizationAccountAccessRole to the master account from the member account IAM for trusted entity and permission.
Ensure that the role name is OrganizationAccountAccessRole , add description based on your preference
OrganizationAccountAccessRole and click the create icon.
For an existing AWS account, the admin needs to accept the invitation sent by the master account to join the organization.
- After putting the correct login credentials, you will be successfully login into the member account as a Federated user*
This enable to create the OU(Organizational Unit) within the root container of the organization. Members account can be grouped into the OU.
SCP is used to perform permission across member accounts, the permission given should also be allowed in the IAM of the member accounts.
SCP basically restricts the access to AWS services prior before the IAM permission takes over.
By default, the SCP is disabled in the organization.
Thanks for reading!!!