SimAWSby ShahriarLabs
Search

AWS Organizations

Organizations

You need to centrally manage, govern, and consolidate billing across multiple AWS accounts.

Global serviceConcept reference · no service console simulation

Reach for it when

  • Consolidating billing across multiple development, staging, and production AWS accounts to get volume discounts.
  • Enforcing security guardrails across accounts using Service Control Policies (SCPs).
  • Automating the creation of new AWS accounts for different business units or engineering teams.

Do not reach for it when

  • Managing permissions for individual users within a single AWS account — use IAM instead.
  • Configuring network routing and connectivity between different AWS accounts — use Transit Gateway instead.
  • Deploying and managing multi-region application resources — use CloudFormation StackSets instead.

Alternatives, and how to choose

ServicePick it instead when
IAMChoose it when managing identity permissions and resource access control within a single AWS account.
Control TowerChoose it when you need a pre-packaged landing zone framework to set up multiple accounts.

How you pay

The model
Free service to use; there are no additional charges for creating organizations or managing accounts.
The line item that surprises people
Consolidating accounts can cause data transfer charges to cross accounts, creating hard-to-trace billing lines.

What trips people up

  • Service Control Policies (SCPs) restrict permissions but do not grant them; you still need IAM policies in target accounts.
  • Removing an account from an organization requires that account to have a valid payment method configured.
  • Applying a restrictive SCP to the root organization unit can lock out administrators in member accounts from core actions.

Verify the live service

This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.