Organizations
Organizations is an account management service that enables you to consolidate multiple AWS accounts into an organization that you create and centrally manage.
As an administrator of an organization, you can create accounts in your organization and invite existing accounts to join the organization.
Organizations has two available feature sets:
All features - With all features enabled, you can use the advanced account management features available in Organizations.
Consolidated Billing features.
Consolidated billing - A feature where you can use the management account of your organization to consolidate and pay for all member accounts. In consolidated billing, management accounts can also access the billing information, account information, and account activity of member accounts in their organization.
Organizational Unites (OUs) - Hierarchical grouping of your accounts to meet your budgetary, security, or compliance needs. You can group your accounts into organizational units (OUs) and attach different access policies to each OU. You can nest OUs within other OUs to a depth of five levels.
Service Control Policies (SCPs)
They help you to ensure your accounts stay within your organization’s access control guidelines.
SCPs alone are not sufficient to granting permissions to the accounts in your organization.
No permissions are granted by an SCP.
An SCP defines a guardrail, or sets limits, on the actions that the account's administrator can delegate to the IAM users and roles in the affected accounts.
Last updated
Was this helpful?