Search code examples
amazon-web-servicesamazon-iamaws-organizations

what is the significance of having an member account in AWS Organization?


What is the real use of having member account to be attached with particular Organizational unit? We can still manage the permission by attaching it to OUs.


Solution

  • There are a few economies of scale that may be reaped by being part of an OU:

    1. Organization CloudTrail -- affords you single place control of all CloudTrails across the OU. This mean aggregation and management is simpler.
    2. Permission control via SCP - If there are proscribe actions then you can deny them at the OU. This way even when policies in the individual accounts grant the proscribed actions they are never available.
      1. Billing - single view of billing across accounts is the most oft sited benefit.