#AwsControlTower
AWS Control Tower introduces a Controls Dedicated experience

AWS Control Tower now offers Control Only Experience, enabling faster governance setup for established multi-account environments by providing access to AWS managed...

#AWS #AwsConfig #AwsControlTower #AwsOrganizations #ManagementTools
AWS Control Tower introduces a Controls Dedicated experience
AWS Control Tower now offers Control Only Experience, enabling faster governance setup for established multi-account environments by providing access to AWS managed controls without requiring a full landing zone implementation.
aws.amazon.com
November 19, 2025 at 8:05 PM
🆕 AWS Control Tower adds 176 new Security Hub controls for better security, cost, and governance. Enable them via the Control Catalog. For more, check the AWS Control Tower User Guide.

#AWS #AwsSecurityHub #AwsGovcloudUs #AwsControlTower
Announcing 176 new AWS Security Hub controls in AWS Control Tower
Today, AWS announces that AWS Control Tower supports an additional 176 Security Hub controls in Control Catalog for use cases such as security, cost, durability, and operations. With this launch, you can now search, discover, enable and manage these additional controls directly from AWS Control Tower and govern more use cases for your multi-account environment. To get started, in AWS Control Tower go to the Control Catalog and search for controls with the Control owner filter set to AWS Security Hub , you will then see all the AWS Security Hub controls present in the Catalog. If you find controls that are relevant for you, you can then directly enable them from the AWS Control Tower console. You can also use ListControls, GetControl and EnableControl APIs. You can search the new AWS Config rules in all AWS Regions where AWS Control Tower is available, including AWS GovCloud (US). When you want to deploy a rule, reference the list of supported regions for that rule to see where it can be enabled. To learn more, visit the AWS Control Tower User Guide.
aws.amazon.com
December 18, 2025 at 11:41 PM
🆕 AWS Control Tower adds 279 new Config rules and seven compliance frameworks to boost security and governance in multi-account setups. Access and manage these via the Control Catalog in supported regions.

#AWS #AwsControlTower
AWS Control Tower now supports seven new compliance frameworks and 279 additional AWS Config rules
Today, AWS Control Tower announces support for an additional 279 managed Config rules in Control Catalog for various use cases such as security, cost, durability, and operations. With this launch, you can now search, discover, enable and manage these additional rules directly from AWS Control Tower and govern more use cases for your multi-account environment. AWS Control Tower also supports seven new compliance frameworks in Control Catalog. In addition to existing frameworks, most controls are now mapped to ACSC-Essential-Eight-Nov-2022, ACSC-ISM-02-Mar-2023, AWS-WAF-v10, CCCS-Medium-Cloud-Control-May-2019, CIS-AWS-Benchmark-v1.2, CIS-AWS-Benchmark-v1.3, CIS-v7.1 To get started, go to the Control Catalog and search for controls with the implementation filter AWS Config to view all AWS Config rules in the Catalog. You can enable relevant rules directly using the AWS Control Tower console or the ListControls, GetControl and EnableControl APIs. We've also enhanced control relationship mapping, helping you understand how different controls work together. The updated ListControlMappings API now reveals important relationships between controls - showing which ones complement each other, are alternatives, or are mutually exclusive. For instance, you can now easily identify when a Config Rule (detection) and a Service Control Policy (prevention) can work together for comprehensive security coverage. These new features are available in AWS Regions where AWS Control Tower is available, including AWS GovCloud (US). Reference the list of supported regions for each Config rule to see where it can be enabled. To learn more, visit the AWS Control Tower User Guide.
aws.amazon.com
November 21, 2025 at 5:41 PM
AWS Weekly Roundup: AWS re:Inforce 2025, AWS WAF, AWS Control Tower, and more (June 16, 2025)

Today marks the start of AWS re:Inforce 2025, where security professionals are gathering for three days of technica...

#AWS #Announcements #AwsControlTower #AwsLambda #AwsWaf #Launch #News #WeekInReview
AWS Weekly Roundup: AWS re:Inforce 2025, AWS WAF, AWS Control Tower, and more (June 16, 2025)
Today marks the start of AWS re:Inforce 2025, where security professionals are gathering for three days of technical learning sessions, workshops, and demonstrations. This security-focused conference brings together AWS security specialists who build and maintain the services that organizations rely on for their cloud security needs. AWS Chief Information Security Officer (CISO) Amy Herzog will […]
aws.amazon.com
June 16, 2025 at 5:05 PM
AWS Control Tower introduces a controls-dedicated experience

AWS Control Tower offers the easiest way to manage and govern your environment with AWS managed controls. Starting today, customers can have direct access to these AWS managed controls without requiring a full ...

#AWS #AwsControlTower
AWS Control Tower introduces a controls-dedicated experience
AWS Control Tower offers the easiest way to manage and govern your environment with AWS managed controls. Starting today, customers can have direct access to these AWS managed controls without requiring a full Control Tower deployment. This new experience offers over 750 managed controls that customers can deploy within minutes while maintaining their existing account structure. AWS Control Tower v4.0 introduces direct access to Control Catalog, allowing customers to review available managed controls and deploy them into their existing AWS Organization. With this release, customers now have more flexibility and autonomy over their organizational structure, as Control Tower will no longer enforce a mandatory structure. Additionally, customers will have improved operations such as cleaner resource and permissions management and cost attribution due to the separation of S3 buckets and SNS notifications for the AWS Config and AWS CloudTrail integrations. This controls-focused experience is now available in all AWS Regions where AWS Control Tower is supported. For more information about this new capability see the https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html or contact your AWS account team. For a full list of Regions where AWS Control Tower is available, see the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/.
aws.amazon.com
November 21, 2025 at 6:05 PM
🆕 AWS Config now links rules to CIS, FedRAMP, and NIST frameworks, leveraging AWS Control Tower's Control Catalog for streamlined compliance across AWS Config and Control Tower, available in all commercial regions.

#AWS #AwsControlTower #AwsConfig
AWS Config rules add classifications from AWS Control Tower Control Catalog
Today, AWS Config rules adds classification information from AWS Control Tower Control Catalog to make it easier for you to identify how Config rules map to different compliance frameworks such as CIS-v8.0, FedRAMP-r4, and NIST-CSF-v1.1. AWS Config rules help you automatically evaluate your AWS resource configurations for desired settings, enabling you to assess, audit, and evaluate configurations of your AWS resources. Control Catalog is a feature of AWS Control Tower that enables you to search AWS managed controls and their associated compliance frameworks. Control Catalog has classifications including Domain (such as "Data Protection"), Objective (such as "Data Encryption"), and common control (such as "Encrypt data at rest") to help you better understand the purpose of a control. Today’s launch maps AWS Config rules to the specific compliance frameworks available in AWS Control Tower Control Catalog (CIS-v8.0, FedRAMP-r4, ISO-IEC-27001:2013-Annex-A, NIST-CSF-v1.1, NIST-SP-800-171-r2, PCI-DSS-v4.0, SSAE-18-SOC-2-Oct-2023), adding classification information (Domain, Objective, common control) to each AWS Config rule. If you're using AWS Config, you'll now see the same classification information in the AWS Config Console and in the AWS Control Tower Control Catalog, ensuring a unified experience across your AWS environment. This alignment between AWS Control Tower and AWS Config allows for seamless integration and more efficient management of your compliance and security posture. AWS Config rules with classifications from AWS Control Tower Control Catalog are available in all AWS Commercial regions where AWS Config and AWS Control Tower are available. To learn more about AWS Config rules and compliance frameworks, visit the AWS Config documentation.
aws.amazon.com
June 30, 2025 at 8:11 PM
AWS Control Tower Account Factory for Terraform now re-applies customizations when accounts move between OUs

AWS Control Tower Account Factory for Terraform (AFT) can now automatically re-apply an account's customizations when that account moves to a different Organization...

#AWS #AwsControlTower
AWS Control Tower Account Factory for Terraform now re-applies customizations when accounts move between OUs
AWS Control Tower Account Factory for Terraform (AFT) can now automatically re-apply an account's customizations when that account moves to a different Organizational Unit (OU). Previously, moving an enrolled account between OUs required manually triggering customization re-application, creating operational overhead and risk of configuration drift. With this capability, you can opt in to automatic re-application in your AFT deployment, so accounts stay consistent with their OU-specific configuration as soon as they're moved. To enable this capability, set aft_customization_triggers = ["account_move"] in your AFT configuration. The re-application workflow skips the bootstrap and provisioning phases, running only global and account-level customizations for faster execution. Individual accounts can be excluded from this behavior by setting account_skip_customization_triggers = "true", giving teams precise control over which accounts participate in automated re-application. This release also includes additional improvements: support for custom Terraform Cloud and Enterprise workspace naming variables, tighter access controls on the AFT logging bucket, and improved scaling for large-scale AWS Enterprise Support enrollment. Organizations enforcing compliance or security baselines tied to OU membership will benefit most from these combined enhancements. This capability is available today across all AWS regions where AWS Control Tower Account Factory for Terraform is offered. To learn more about enabling automatic customization re-application and upgrading to the latest AFT release, visit the https://docs.aws.amazon.com/controltower/latest/userguide/aft-overview.html and review the https://github.com/aws-ia/terraform-aws-control_tower_account_factory/releases.
aws.amazon.com
July 16, 2026 at 6:05 PM
🆕 AWS Control Tower now offers direct access to over 750 managed controls for easier governance without full deployment, enhanced flexibility, and improved resource management. Available in all supported regions.

#AWS #AwsControlTower
AWS Control Tower introduces a controls-dedicated experience
AWS Control Tower offers the easiest way to manage and govern your environment with AWS managed controls. Starting today, customers can have direct access to these AWS managed controls without requiring a full Control Tower deployment. This new experience offers over 750 managed controls that customers can deploy within minutes while maintaining their existing account structure. AWS Control Tower v4.0 introduces direct access to Control Catalog, allowing customers to review available managed controls and deploy them into their existing AWS Organization. With this release, customers now have more flexibility and autonomy over their organizational structure, as Control Tower will no longer enforce a mandatory structure. Additionally, customers will have improved operations such as cleaner resource and permissions management and cost attribution due to the separation of S3 buckets and SNS notifications for the AWS Config and AWS CloudTrail integrations. This controls-focused experience is now available in all AWS Regions where AWS Control Tower is supported. For more information about this new capability see the AWS Control Tower User Guide or contact your AWS account team. For a full list of Regions where AWS Control Tower is available, see the AWS Region Table.
aws.amazon.com
November 21, 2025 at 5:42 PM
🆕 AWS Control Tower now supports AWS PrivateLink, enabling secure API access within VPCs without public internet exposure, enhancing compliance and security for multi-account environments. Available in all regions where AWS Control Tower operates.

#AWS #AwsGovcloudUs #AwsControlTower
AWS Control Tower adds support for AWS PrivateLink
AWS Control Tower and Control Catalog APIs now come with AWS PrivateLink support, allowing you to invoke AWS Control Tower and Control Catalog APIs from within your Amazon Virtual Private Cloud (VPC) without traversing the public internet. AWS PrivateLink provides private connectivity between virtual private clouds (VPCs), supported services and resources, and your on-premises networks, without exposing your traffic to the public internet. AWS Control Tower simplifies managing a secure, compliant multi-account environment within an AWS Organization. Customers enable AWS services like Config, CloudTrail, and Identity Center with AWS-recommended configurations through Control Tower, ensuring that all accounts in each Organization Unit (OU) adhere to the same baseline defined by the IT administrator. Applications running inside these accounts are governed via managed controls deployed through the Control Catalog in Control Tower, ensuring compliance with business requirements and regulatory policies on an ongoing basis. AWS PrivateLink support for AWS Control Tower is available in all AWS Regions where AWS Control Tower is available. For a full list of AWS regions where AWS Control Tower is available, see AWS Region Table. You can start deploying AWS Control Tower from the console or using AWS Control Tower APIs.
aws.amazon.com
June 30, 2025 at 10:40 PM
🆕 AWS Control Tower now provides account-level reporting for baseline APIs, enabling programmatic views for governed accounts, drift detection, and IaC management of organizational units and accounts. Available in all regions.

#AWS #AwsGovcloudUs #AwsControlTower
AWS Control Tower introduces account-level reporting for baseline APIs
AWS Control Tower customers can now programmatically view statuses for their governed accounts via baseline APIs. The AWS Control Tower baseline contains best practice configurations, controls, and resources required for governance. When you enable this baseline on an organizational unit (OU), member accounts within the OU will be enrolled under governance. With this new experience, you can use baseline status to view enrollment for your accounts and use drift status to identify when account and OU baseline configurations are out of sync. In addition to seeing statuses for your accounts and OUs in the AWS Control Tower console, you can the ListEnabledBaselines API to view statuses for your enabled baselines. To view statuses for individual accounts, use the “includeChildren” flag. You can filter by these statuses to view only the accounts and OUs which require your attention. These APIs include AWS CloudFormation support, allowing you to build automations to manage your OUs and accounts with infrastructure as code (IaC). To learn more about these APIs, review Baselines and API References in the AWS Control Tower User Guide. Baseline APIs and the newly launched reporting capabilities are available in all AWS Regions where AWS Control Tower is available. For a list of AWS Regions where AWS Control Tower is available, see the AWS Region Table.
aws.amazon.com
May 14, 2025 at 7:40 PM
Announcing 176 new AWS Security Hub controls in AWS Control Tower

Today, AWS announces that AWS Control Tower supports an additional 176 Security Hub controls in Control Catalog for use cases such as security, cost, durability, and operati...

#AWS #AwsSecurityHub #AwsGovcloudUs #AwsControlTower
Announcing 176 new AWS Security Hub controls in AWS Control Tower
Today, AWS announces that AWS Control Tower supports an additional 176 Security Hub controls in Control Catalog for use cases such as security, cost, durability, and operations. With this launch, you can now search, discover, enable and manage these additional controls directly from AWS Control Tower and govern more use cases for your multi-account environment. To get started, in AWS Control Tower go to the Control Catalog and search for controls with the Control owner filter set to AWS Security Hub , you will then see all the AWS Security Hub controls present in the Catalog. If you find controls that are relevant for you, you can then directly enable them from the AWS Control Tower console. You can also use ListControls, GetControl and EnableControl APIs. You can search the new AWS Config rules in all https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where AWS Control Tower is available, including AWS GovCloud (US). When you want to deploy a rule, reference the list of supported regions for that rule to see where it can be enabled. To learn more, visit the https://docs.aws.amazon.com/controltower/latest/controlreference/config-controls.html.
aws.amazon.com
December 19, 2025 at 12:05 AM
🆕 AWS Control Tower is now available in the Asia Pacific (New Zealand) Region, expanding to 34 regions. It simplifies multi-account setup, governance, and compliance, enabling secure, scalable environments within 30 minutes.

#AWS #AwsControlTower
AWS Control Tower is now available in AWS Asia Pacific (New Zealand) Region
Starting today, customers can use AWS Control Tower in the AWS Asia Pacific (New Zealand) Region. With this launch, AWS Control Tower is available in 34 AWS Regions and the AWS GovCloud (US) Regions. AWS Control Tower offers the easiest way to set up and govern a secure, multi-account AWS environment. It simplifies AWS experiences by orchestrating multiple AWS services on your behalf while maintaining the security and compliance needs of your organization. You can set up a multi-account AWS environment within 30 minutes or less, govern new or existing account configurations, gain visibility into compliance status, and enforce controls at scale. If you are new to AWS Control Tower, you can launch it today in any of the supported regions and you can use AWS Control Tower to govern your multi-account environment in all supported Regions. If you are already using AWS Control Tower and you want to extend its governance features to the newly supported regions in your accounts, you can go to the settings page in your AWS Control Tower dashboard, select your regions, and update your landing zone. Once you update all your governed accounts, your landing zone, managed accounts, and registered OUs will be under governance in the new region(s). For a full list of Regions where AWS Control Tower is available, see the AWS Region Table. To learn more, visit the AWS Control Tower homepage or see the AWS Control Tower User Guide.
aws.amazon.com
October 29, 2025 at 6:40 PM
AWS Control Tower adds support for AWS PrivateLink

AWS Control Tower and Control Catalog APIs now come with https://aws.amazon.com/privatelink/ support, allowing you to invoke AWS Control Tower and Control Catalog APIs from within your Amazon Virtual Priva...

#AWS #AwsGovcloudUs #AwsControlTower
AWS Control Tower adds support for AWS PrivateLink
AWS Control Tower and Control Catalog APIs now come with https://aws.amazon.com/privatelink/ support, allowing you to invoke AWS Control Tower and Control Catalog APIs from within your Amazon Virtual Private Cloud (VPC) without traversing the public internet. AWS PrivateLink provides private connectivity between virtual private clouds (VPCs), supported services and resources, and your on-premises networks, without exposing your traffic to the public internet. AWS Control Tower simplifies managing a secure, compliant multi-account environment within an AWS Organization. Customers enable AWS services like Config, CloudTrail, and Identity Center with AWS-recommended configurations through Control Tower, ensuring that all accounts in each Organization Unit (OU) adhere to the same baseline defined by the IT administrator. Applications running inside these accounts are governed via managed controls deployed through the Control Catalog in Control Tower, ensuring compliance with business requirements and regulatory policies on an ongoing basis. AWS PrivateLink support for AWS Control Tower is available in all AWS Regions where AWS Control Tower is available. For a full list of AWS regions where AWS Control Tower is available, see https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/. You can start deploying AWS Control Tower from the console or using AWS Control Tower https://docs.aws.amazon.com/controltower/latest/APIReference/Welcome.html.  
aws.amazon.com
June 30, 2025 at 11:05 PM
AWS Config rules add classifications from AWS Control Tower Control Catalog

Today, AWS Config rules adds classification information from AWS Control Tower Control Catalog to make it easier for you to identify how Config rules map to different compliance framew...

#AWS #AwsControlTower #AwsConfig
AWS Config rules add classifications from AWS Control Tower Control Catalog
Today, AWS Config rules adds classification information from AWS Control Tower Control Catalog to make it easier for you to identify how Config rules map to different compliance frameworks such as CIS-v8.0, FedRAMP-r4, and NIST-CSF-v1.1. AWS Config rules help you automatically evaluate your AWS resource configurations for desired settings, enabling you to assess, audit, and evaluate configurations of your AWS resources. Control Catalog is a feature of AWS Control Tower that enables you to search AWS managed controls and their associated compliance frameworks. Control Catalog has classifications including Domain (such as "Data Protection"), Objective (such as "Data Encryption"), and common control (such as "Encrypt data at rest") to help you better understand the purpose of a control. Today’s launch maps AWS Config rules to the specific compliance frameworks available in AWS Control Tower Control Catalog (CIS-v8.0, FedRAMP-r4, ISO-IEC-27001:2013-Annex-A, NIST-CSF-v1.1, NIST-SP-800-171-r2, PCI-DSS-v4.0, SSAE-18-SOC-2-Oct-2023), adding classification information (Domain, Objective, common control) to each AWS Config rule. If you're using AWS Config, you'll now see the same classification information in the AWS Config Console and in the AWS Control Tower Control Catalog, ensuring a unified experience across your AWS environment. This alignment between AWS Control Tower and AWS Config allows for seamless integration and more efficient management of your compliance and security posture. AWS Config rules with classifications from AWS Control Tower Control Catalog are available in all AWS Commercial regions where AWS Config and AWS Control Tower are available. To learn more about AWS Config rules and compliance frameworks, visit the AWS Config https://docs.aws.amazon.com/config/latest/developerguide/evaluate-config.html.
aws.amazon.com
June 30, 2025 at 8:05 PM
AWS Control Tower now supports seven new compliance frameworks and 279 additional AWS Config rules

Today, AWS Control Tower announces support for an additional 279 managed Config rules in Control Catalog for various use cases such as security, cost, durability, and opera...

#AWS #AwsControlTower
AWS Control Tower now supports seven new compliance frameworks and 279 additional AWS Config rules
Today, AWS Control Tower announces support for an additional 279 managed Config rules in Control Catalog for various use cases such as security, cost, durability, and operations. With this launch, you can now search, discover, enable and manage these additional rules directly from AWS Control Tower and govern more use cases for your multi-account environment. AWS Control Tower also supports seven new compliance frameworks in Control Catalog. In addition to existing frameworks, most controls are now mapped to ACSC-Essential-Eight-Nov-2022, ACSC-ISM-02-Mar-2023, AWS-WAF-v10, CCCS-Medium-Cloud-Control-May-2019, CIS-AWS-Benchmark-v1.2, CIS-AWS-Benchmark-v1.3, CIS-v7.1 To get started, go to the Control Catalog and search for controls with the implementation filter AWS Config to view all AWS Config rules in the Catalog. You can enable relevant rules directly using the AWS Control Tower console or the ListControls, GetControl and EnableControl APIs. We've also enhanced control relationship mapping, helping you understand how different controls work together. The updated ListControlMappings API now reveals important relationships between controls - showing which ones complement each other, are alternatives, or are mutually exclusive. For instance, you can now easily identify when a Config Rule (detection) and a Service Control Policy (prevention) can work together for comprehensive security coverage. These new features are available in https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where AWS Control Tower is available, including AWS GovCloud (US). Reference the list of supported regions for each Config rule to see where it can be enabled. To learn more, visit the https://docs.aws.amazon.com/controltower/latest/controlreference/config-controls.html.
aws.amazon.com
November 21, 2025 at 6:05 PM
AWS Control Tower is now available in AWS Asia Pacific (New Zealand) Region

Starting today, customers can use AWS Control Tower in the AWS Asia Pacific (New Zealand) Region. With this launch, AWS Control Tower is available in 34 AWS Regions and the AWS GovCloud (US) Regi...

#AWS #AwsControlTower
AWS Control Tower is now available in AWS Asia Pacific (New Zealand) Region
Starting today, customers can use AWS Control Tower in the AWS Asia Pacific (New Zealand) Region. With this launch, AWS Control Tower is available in 34 AWS Regions and the AWS GovCloud (US) Regions. AWS Control Tower offers the easiest way to set up and govern a secure, multi-account AWS environment. It simplifies AWS experiences by orchestrating multiple AWS services on your behalf while maintaining the security and compliance needs of your organization. You can set up a multi-account AWS environment within 30 minutes or less, govern new or existing account configurations, gain visibility into compliance status, and enforce controls at scale. If you are new to AWS Control Tower, you can launch it today in any of the supported regions and you can use AWS Control Tower to govern your multi-account environment in all supported Regions. If you are already using AWS Control Tower and you want to extend its governance features to the newly supported regions in your accounts, you can go to the settings page in your AWS Control Tower dashboard, select your regions, and update your landing zone. Once you https://docs.aws.amazon.com/controltower/latest/userguide/configuration-updates.html#deploying-to-new-region, your landing zone, managed accounts, and registered OUs will be under governance in the new region(s). For a full list of Regions where AWS Control Tower is available, see the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/. To learn more, visit the AWS Control Tower homepage or see the https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html.
aws.amazon.com
October 29, 2025 at 7:05 PM
AWS Control Tower improves Hooks management for proactive controls and extends proactive controls support in additional regions

Today, we are excited to release an improved AWS CloudFormation Hooks management capability for AWS Control Tower proactive controls. With this...

#AWS #AwsControlTower
AWS Control Tower improves Hooks management for proactive controls and extends proactive controls support in additional regions
Today, we are excited to release an improved AWS CloudFormation Hooks management capability for AWS Control Tower proactive controls. With this release, Hooks deployed for proactive controls will now be managed by AWS Control Tower. Additionally, we are releasing proactive controls in AWS Canada West (Calgary) and Asia Pacific (Malaysia) regions. These controls help you meet control objectives such as establish logging and monitoring, encrypt data at rest, or improve resiliency. To see a full list of the proactive controls, see the https://docs.aws.amazon.com/controltower/latest/userguide/proactive-controls.html. AWS Control Tower’s proactive control capabilities leverage AWS CloudFormation Hooks to identify and block non-compliant resources proactively before AWS CloudFormation provisions them. Previously, proactive control deployed Hooks were protected to ensure only AWS Control Tower can modify them, preventing customers from authoring their own Hooks. With this release, proactive control deployed Hooks are now directly managed by the AWS Control Tower service, allowing customers to author their own Hooks, while also benefiting from the AWS Control Tower proactive controls. AWS Control Tower’s proactive controls are available in all AWS commercial Regions where AWS Control Tower is available. For a full list of AWS Regions where AWS Control Tower is available, see https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/. You can start deploying the AWS Control Tower controls from the console or using https://docs.aws.amazon.com/controltower/latest/APIReference/Welcome.html.  
aws.amazon.com
November 21, 2024 at 1:05 AM
🆕 AWS Control Tower now re-applies Terraform customizations when accounts move between OUs, cutting manual work and drift. Enable with aft_customization_triggers = ["account_move"]. Available in all regions with AFT. See documentation for details.

#AWS #AwsControlTower
AWS Control Tower Account Factory for Terraform now re-applies customizations when accounts move between OUs
AWS Control Tower Account Factory for Terraform (AFT) can now automatically re-apply an account's customizations when that account moves to a different Organizational Unit (OU). Previously, moving an enrolled account between OUs required manually triggering customization re-application, creating operational overhead and risk of configuration drift. With this capability, you can opt in to automatic re-application in your AFT deployment, so accounts stay consistent with their OU-specific configuration as soon as they're moved. To enable this capability, set aft_customization_triggers = ["account_move"] in your AFT configuration. The re-application workflow skips the bootstrap and provisioning phases, running only global and account-level customizations for faster execution. Individual accounts can be excluded from this behavior by setting account_skip_customization_triggers = "true", giving teams precise control over which accounts participate in automated re-application. This release also includes additional improvements: support for custom Terraform Cloud and Enterprise workspace naming variables, tighter access controls on the AFT logging bucket, and improved scaling for large-scale AWS Enterprise Support enrollment. Organizations enforcing compliance or security baselines tied to OU membership will benefit most from these combined enhancements. This capability is available today across all AWS regions where AWS Control Tower Account Factory for Terraform is offered. To learn more about enabling automatic customization re-application and upgrading to the latest AFT release, visit the AFT documentation and review the AFT release notes on GitHub.
aws.amazon.com
July 16, 2026 at 6:10 PM
#うひーメモ
2023-12-08 00:13:04
[2023年版] AWS Control Towerのメンバーアカウントを閉鎖(削除・解約)する
#技術系ブログ等
#awscontroltower
#maruyamasashi
#アカウント
[2023年版] AWS Control Towerのメンバーアカウントを閉鎖(削除・解約)する
こんにちは丸屋正志MaruyaMasashiです今日もブロックを掘ったり積み上げたり匠に壊されたりしていますかこのブログで実施することこのブログでは不要になったAWSControlTower
dev.classmethod.jp
December 7, 2023 at 3:13 PM
#うひーメモ
2023-12-07 00:05:53
API を使って AWS Control Towerのランディングゾーンを設定してみた #AWSreInvent
#技術系ブログ等
#awscontroltower
#awsreinvent
#たかやま
API を使って AWS Control Towerのランディングゾーンを設定してみた #AWSreInvent
こんにちはたかやまです先日AWSControlTowerのランディングゾーンをAPIで設定できるようになりましたリリース時はドキュメントAPI周りが整っていなかったため実際に構築まで行えなかったので今回そ
dev.classmethod.jp
December 6, 2023 at 3:05 PM
#うひーメモ
2023-12-01 00:38:09
AWS Control Tower における OU に対してリージョン制限を実施するコントロールの例外設定を試してみた
#技術系ブログ等
#awscontroltower
#アップデート
#コントロール
AWS Control Tower における OU に対してリージョン制限を実施するコントロールの例外設定を試してみた
先日のAWSControlTowerのアップデートによりランディングゾーン設定のリージョン制限とは別にOUに対するリージョン制限ができるコントロールが追加されましたこのブログでは本コントロールにおけるオ
dev.classmethod.jp
November 30, 2023 at 3:38 PM
#うひーメモ
2023-11-28 16:07:15
[アップデート] AWS Control Tower に新たに 65 個のコントロールが追加されて OU 単位でのリージョン制限もできるようになりました #AWSreInvent
#技術系ブログ等
#アップデート
#awscontroltower
#reinventawscontroltower
[アップデート] AWS Control Tower に新たに 65 個のコントロールが追加されて OU 単位でのリージョン制限もできるようになりました #AWSreInvent
AWSControlTowerに新たに個のコントロールが追加されましたその中にはOU単位でリージョン制限ができるコントロールも存在していますこれまではAWSControlTower環境では組
dev.classmethod.jp
November 28, 2023 at 7:07 AM
#うひーメモ
2023-11-27 18:07:28
[アップデート]API を使用して AWS Control Tower ランディング ゾーンの操作を自動化が可能になりました #AWSreInvent
#技術系ブログ等
#アップデート
#awscontroltower
#awsreinvent
[アップデート]API を使用して AWS Control Tower ランディング ゾーンの操作を自動化が可能になりました #AWSreInvent
こんにちはたかやまですいままでControlTowerのランディングゾーンの操作はコンソールからしかできませんでしたが今回アップデートによりついにControlTowerのランディングゾーンの操作がAPIより
dev.classmethod.jp
November 27, 2023 at 9:07 AM
#うひーメモ
2023-11-12 03:00:49
[アップデート]AWS Control TowerにOUで有効化されているコントロールへタグ付けできるAPIが追加されました。
#技術系ブログ等
#アップデート
#awscontroltower
#コントロール
[アップデート]AWS Control TowerにOUで有効化されているコントロールへタグ付けできるAPIが追加されました。
あしざわです本日AWSControlTowerのAPIにアップデートがありOUで有効化されているコントロールへタグ付けできる新しいAPIが追加されました追加されたAPIは以下つですListTagsF
dev.classmethod.jp
November 11, 2023 at 6:00 PM
#うひーメモ
2023-11-01 17:12:52
AWS Configを使用した「require-tag」ポリシーの組織全体適用手順
#Program
#awsconfig
#awsconf
#awscontroltower
AWS Configを使用した「require-tag」ポリシーの組織全体適用手順
AWSConfigを使用したrequiretagポリシーの組織全体適用手順前提AWSControlTowerを使用し組織全体を管理していること自動的に生成されるAWSConf
qiita.com
November 1, 2023 at 8:12 AM