AWS Organizations
Organizations
You need to centrally manage, govern, and consolidate billing across multiple AWS accounts.
Reach for it when
- Consolidating billing across multiple development, staging, and production AWS accounts to get volume discounts.
- Enforcing security guardrails across accounts using Service Control Policies (SCPs).
- Automating the creation of new AWS accounts for different business units or engineering teams.
Do not reach for it when
- Managing permissions for individual users within a single AWS account — use IAM instead.
- Configuring network routing and connectivity between different AWS accounts — use Transit Gateway instead.
- Deploying and managing multi-region application resources — use CloudFormation StackSets instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| IAM | Choose it when managing identity permissions and resource access control within a single AWS account. |
| Control Tower | Choose it when you need a pre-packaged landing zone framework to set up multiple accounts. |
How you pay
- The model
- Free service to use; there are no additional charges for creating organizations or managing accounts.
- The line item that surprises people
- Consolidating accounts can cause data transfer charges to cross accounts, creating hard-to-trace billing lines.
What trips people up
- Service Control Policies (SCPs) restrict permissions but do not grant them; you still need IAM policies in target accounts.
- Removing an account from an organization requires that account to have a valid payment method configured.
- Applying a restrictive SCP to the root organization unit can lock out administrators in member accounts from core actions.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.