AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Security & identity

Multi-account strategy and governance

2 min readChapter 07 of 48By Bipin Singh

Mature AWS customers don't put everything in one account. Separate accounts give the strongest boundary for security, billing and blast radius. The exam expects you to know how to govern many accounts centrally.

Why multiple accounts

AWS Organizations

Organizations groups accounts under a management account:

Service control policies (SCPs)

SCPs set the maximum permissions for accounts in an OU. They don't grant anything.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DenyLeavingAllowedRegions",
      "Effect": "Deny",
      "NotAction": ["iam:*", "organizations:*", "sts:*", "support:*", "cloudfront:*", "route53:*"],
      "Resource": "*",
      "Condition": { "StringNotEquals": { "aws:RequestedRegion": ["ap-south-1", "eu-west-1"] } }
    },
    {
      "Sid": "ProtectCloudTrail",
      "Effect": "Deny",
      "Action": ["cloudtrail:StopLogging", "cloudtrail:DeleteTrail"],
      "Resource": "*"
    }
  ]
}

Key facts:

Key idea

"Prevent any account from doing X, even administrators" → SCP. "Limit what a specific developer role can grant" → permissions boundary.

AWS Control Tower

Control Tower sets up and governs a multi-account environment following AWS best practices — a landing zone:

Exam cue: "set up a secure multi-account environment quickly with best-practice guardrails" → Control Tower.

Sharing and standardising

Service Purpose
AWS Resource Access Manager (RAM) Share resources across accounts — e.g. VPC subnets, Transit Gateways, Route 53 Resolver rules, License Manager configurations
AWS Service Catalog Publish approved products (CloudFormation templates) that users can launch self-service within guardrails
Tag policies Enforce consistent tagging across accounts (important for cost allocation)
AWS License Manager Track and enforce software licence usage (e.g. bring-your-own-licence)

A typical account structure

Management account (billing, Organizations only)
├── Security OU
│   ├── Log Archive account   (central CloudTrail / Config logs)
│   └── Audit / Security account (GuardDuty, Security Hub delegated admin)
├── Infrastructure OU
│   └── Network account (Transit Gateway, Direct Connect, shared VPCs via RAM)
├── Workloads OU
│   ├── Production accounts
│   └── Non-production accounts
└── Sandbox OU (experiments, strict budgets)

Exam patterns

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me