AWSHow-To & HardeningRetrospectives

How to Set Up AWS Control Tower With Preventive and Detective Guardrails

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2019, written in 2026 with the benefit of hindsight.

AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.

Before you start

  • Decide your home region and which regions you will allow.
  • Plan your organizational units (for example Security, Infrastructure, Workloads-Prod, Workloads-NonProd, Sandbox).
  • Have email addresses ready for the Log Archive and Audit accounts.
  • If you already use AWS Organizations, review existing SCPs and accounts to enroll.

Step 1: Launch the landing zone

From the management account, open Control Tower and set up the landing zone. Choose:

  • Home region and governed regions.
  • Region deny control to block unused regions.
  • KMS encryption for logs.
  • Log retention periods.

Step 2: Configure identity

Use IAM Identity Center with your corporate identity provider (such as Entra ID) and assign permission sets by group.

Step 3: Enable controls

Control Tower has three kinds of controls:

  • Preventive (SCPs): stop actions, such as disabling CloudTrail.
  • Detective (Config rules): flag non-compliant resources, such as unencrypted EBS volumes.
  • Proactive (CloudFormation hooks): block non-compliant resources before deployment.

Start with all mandatory and strongly recommended controls, then add elective controls relevant to your environment.

Step 4: Use Account Factory

Create new accounts through Account Factory so every account gets the baseline. Consider Account Factory for Terraform if your team uses Terraform.

Step 5: Add security services

Delegate GuardDuty, Security Hub and IAM Access Analyzer to the Audit (security tooling) account.

aws control tower setupAWS Control Tower GA2019

More on this story