Control Tower Pros

  1. Self Service model –  A ‘better’ supported service – with shorter AWS support response times (compared to Landing Zones)
  2. Lower Complexity – most customers report smoother execution (compared to Landing Zones)
  3. All the Add Ons supported by Landing Zones are supported in Control Tower (Okta, AD) – as well as some additional ones (Transit Gateway, Elasticsearch). 
  4. Integrated with Cloudtrail and cloudwatch (just like Landing zones).

Control Tower Limitations

  1. Still doesn’t handle existing account structures. May be part of a future release (not sure when).
  2. Only available in 4 regions. Not available in Gov cloud
  3. No programmatic API. All actions are through the management console.

Pricing

  1. The cost is only for resources spun up, both LZ and CT are free). In the past, Landing Zone spun up resources would cost anywhere between $200 – $600 / month – depending on whether you spun up Managed AD or not.

Anuj holds professional certifications in Google Cloud, AWS as well as certifications in Docker and App Performance Tools such as New Relic. He specializes in Cloud Security, Data Encryption and Container Technologies.

Initial Consultation

Anuj Varma – who has written posts on Anuj Varma, Hands-On Technology Architect, Clean Air Activist.