AWS Multi-Account Landing Zone Design and Operations: Building a Practical Architecture

This is a hands-on course for systematically designing and building a multi-account environment based on AWS Organizations. It covers the entire landing zone implementation process, from designing the OU structure and Transit Gateway network architecture to the criteria for choosing between Control Tower and LZA, as well as strategies for incorporating existing accounts. Beyond simple console operations, you will develop the ability to make design decisions suited to your organization’s circumstances and establish an operational governance framework.

1 learners are taking this course

Level Intermediate

Course period Unlimited

Accounting
Accounting
teamcity
teamcity
api-gateway
api-gateway
aws-iam
aws-iam
Promotional Page Creation
Promotional Page Creation
Accounting
Accounting
teamcity
teamcity
api-gateway
api-gateway
aws-iam
aws-iam
Promotional Page Creation
Promotional Page Creation

What you will gain after the course

  • Create a document outlining an OU structure aligned with organizational requirements, account separation criteria, and a guardrail implementation plan.

  • Designing the Egress, Inspection, and DNS Architecture for a Transit Gateway–Based Network Landing Zone

  • Establish an operating framework for incorporating existing accounts, including the identification of pre-integration checks and drift management.

Course Introduction


Most organizations start with a single account. A year later, they have three, and three years later, 40. No one made a wrong decision along the way. Each decision was reasonable, yet the result is a state that no one can explain as a whole.

Logs become scattered across accounts, and account owners can delete their own logs. Permissions multiply with the number of accounts and users. Security standards exist only in documents and are not reflected in actual accounts. The bills arrive accurately, but there is no basis for determining which department’s costs they belong to.

This course covers how to move beyond that state. However, it is not a course that tells you which buttons to click in the console. It focuses on design decisions such as how to divide accounts, which controls to implement and in what order, and how to configure the network. Tools may change, but these decision-making criteria remain.

Each session includes a practical checklist and slides covering common mistakes. The course is structured so that you can immediately assess the state of your organization after completing it.


Recommended for people who...

  • Infrastructure engineers who feel uneasy because their AWS accounts keep increasing without any management standards

  • Platform teams stuck at the design stage ahead of transitioning to a multi-account setup or introducing a landing zone

  • For those who have turned on Control Tower but don’t know what to do next

  • Individuals repeatedly collecting account-specific materials for audits or security reviews

  • Organizations that need to enforce control requirements across all accounts for regulatory compliance.

  • Those who want to establish a rationale for multi-account design as cloud architects


After taking this course


  • You can document an OU structure and account separation criteria that fit your organization’s circumstances.

  • You can make an informed decision about whether to use Control Tower, Landing Zone Accelerator, or your own IaC.

  • You can create a plan to apply guardrails, including SCPs and RCPs, incrementally without causing incidents.

  • You can design the egress, inspection, and DNS architecture of a Transit Gateway–based network landing zone.

  • You can identify the pre-check items and potential failure points in advance when incorporating existing operating accounts.

  • You can establish an operational framework covering drift, version updates, and cost governance.

Recommended for
these people

Who is this course right for?

  • Cloud architects and DevOps engineers responsible for building AWS multi-account environments

  • Cloud team leaders considering adopting Control Tower or Landing Zone Accelerator

  • Infrastructure managers who need to resolve existing AWS account sprawl and establish a governance framework

Need to know before starting?

  • Experience using basic AWS services (VPC, IAM, EC2) and proficiency in operating the console

  • Basic knowledge of networking (routing, subnets, DNS) and experience operating enterprise IT infrastructure

  • Understanding the basic concepts of IaC tools (Terraform, CloudFormation, etc.)

Hello
This is jjangkbg7719

Career Verified

733

Learners

58

Reviews

3

Answers

4.7

Rating

35

Courses

Hello, I'm Frank.

I am an infrastructure engineer who has been wrestling with servers for over 20 years. Starting with Linux server operations, I am now in charge of the cloud infrastructure for a large-scale payment service. My daily life involves migrating from data centers to AWS, managing hundreds of instances, and tracing the causes of failures in the early hours of the morning.

The reason I created this course is simple.

I often received questions like these from those around me: "I managed to connect to the server, but I don't know what to do next." "There are so many instance types; which one should I choose?" These are the exact same points where I got stuck at first. However, when I looked for resources, I found that most of them were written for people who already knew what they were doing.

So I decided to create the course I wish I had when I first started learning.

My lectures are based on three principles.

First, I help you understand rather than memorize. Instead of just listing commands, I explain why we use them in the first place.

Second, I boldly omit unnecessary content. I do not increase the volume by including information that is useless to beginners right now.

Third, I also talk about what doesn't work. Instead of just listing the pros, I clearly point out cases where it might not be a good fit. For someone who has to make decisions in the field, that is more important.

If you feel a sense of "Ah, I should start from here" after listening to the lecture, then my goal has been achieved.

Please feel free to leave any questions you may have at any time.

More

Curriculum

All

16 lectures ∙ (17min)

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

Not enough reviews.
Please write a valuable review that helps everyone!

jjangkbg7719's other courses

Check out other courses by the instructor!

Limited time deal

$3,300.00

70%

$8.80