11 thẻ
SCPs: Không ảnh hưởng Management Account
1. Multi-Account & Organizations
SCPs: Deny List strategy (recommended)
1. Multi-Account & Organizations
SCPs: Kết hợp với Permission Boundaries
1. Multi-Account & Organizations
SCPs: Áp dụng theo OU hierarchy
1. Multi-Account & Organizations
Landing Zone Accounts: Management (billing, org)
1. Multi-Account & Organizations
Landing Zone Accounts: Log Archive (centralized logs)
1. Multi-Account & Organizations
Landing Zone Accounts: Security (GuardDuty, Security Hub)
1. Multi-Account & Organizations
Landing Zone Accounts: Network (Transit Gateway, shared VPC)
1. Multi-Account & Organizations
Cross-Account Access: IAM Roles (recommended)
1. Multi-Account & Organizations
Cross-Account Access: Resource-based policies
1. Multi-Account & Organizations
Cross-Account Access: AWS RAM (resource sharing)
1. Multi-Account & Organizations