All technological notes.
AWS OrganizationsAWS Organizations
Typs of Account
management account
member accounts
Consolidated Billing
management accountreserved instances and Savings Plans discounts across accountsAPI is available to automate AWS account creation




Advantages
Admin
Cross Account Roles for Admin purposesBilling
Log
CloudWatch Logs to central logging accountAudit
CloudTrail on all accounts, send logs to central S3 accountSecurity
SCPService Control Policies (SCP)
IAM policies applied to OU or Accounts to restrict Users and Rolesmanagement account (full admin power)IAMSample:















FULLAWSAccess policy.








