How to Set Up AWS Control Tower With Preventive and Detective Guardrails
Retrospective: this article looks back at events from June 2019, written in 2026 with the benefit of hindsight.
AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.
Before you start
- Decide your home region and which regions you will allow.
- Plan your organizational units (for example Security, Infrastructure, Workloads-Prod, Workloads-NonProd, Sandbox).
- Have email addresses ready for the Log Archive and Audit accounts.
- If you already use AWS Organizations, review existing SCPs and accounts to enroll.
Step 1: Launch the landing zone
From the management account, open Control Tower and set up the landing zone. Choose:
- Home region and governed regions.
- Region deny control to block unused regions.
- KMS encryption for logs.
- Log retention periods.
Step 2: Configure identity
Use IAM Identity Center with your corporate identity provider (such as Entra ID) and assign permission sets by group.
Step 3: Enable controls
Control Tower has three kinds of controls:
- Preventive (SCPs): stop actions, such as disabling CloudTrail.
- Detective (Config rules): flag non-compliant resources, such as unencrypted EBS volumes.
- Proactive (CloudFormation hooks): block non-compliant resources before deployment.
Start with all mandatory and strongly recommended controls, then add elective controls relevant to your environment.
Step 4: Use Account Factory
Create new accounts through Account Factory so every account gets the baseline. Consider Account Factory for Terraform if your team uses Terraform.
Step 5: Add security services
Delegate GuardDuty, Security Hub and IAM Access Analyzer to the Audit (security tooling) account.
- AWS Control Tower Goes GA (June 2019): Guardrails for Multi-Account AWS Platform Changes
- Control Tower Guardrail Selection Checklist How-To & Hardening
- CIO Brief: Governance at Scale — Why Control Tower Matters CIO Briefings