Organizations
- Global Service
- Allow to manage multiple
AWS Account
Main Account
isMaster Account
Master Account
can not be changed- Other account is
Member Account
- Each member can attach only one
Organization
- Consolidated Billing
- For all
Organization Account
- Pricing benefits are calculated by
Consolidated Billing
API
is available to automate creating theAWS Account
- Resource sharing can be done by individual account even though the resource sharing is not enabled by
SCP
SCP
- Service Control Policies
- Use for
White List
andBlack List
theIAM Action
- Applied to
Organization Unit
orAccount Level
- Does not apply to
Master Account
SCP
- By default deny everything
- Need explicit allow to for any action
- Effect of
Service Linked Roles
Service Linked Roles
enableAWS Service
toAWS Organization
SCP
can not affectService Linked Roles
Transfer An Account Between AWS Organization
- Member Account Transfer
- Leave the current organization
- Get invitation from the other organization
- Accept the invitation
- Master Account Transfer
- Remove all the member account
- Delete old organization