Control Tower vs Landing Zones in AWS –High Level Recap
Control Tower Pros
- Self Service model – A ‘better’ supported service – with shorter AWS support response times (compared to Landing Zones)
- Lower Complexity – most customers report smoother execution (compared to Landing Zones)
- All the Add Ons supported by Landing Zones are supported in Control Tower (Okta, AD) – as well as some additional ones (Transit Gateway, Elasticsearch).
- Integrated with Cloudtrail and cloudwatch (just like Landing zones).
Control Tower Limitations
- Still doesn’t handle existing account structures. May be part of a future release (not sure when).
- Only available in 4 regions. Not available in Gov cloud
- No programmatic API. All actions are through the management console.
Pricing
- The cost is only for resources spun up, both LZ and CT are free). In the past, Landing Zone spun up resources would cost anywhere between $200 – $600 / month – depending on whether you spun up Managed AD or not.
Leave a Reply