Introducing AWS Organizations

Поділитися
Вставка
  • Опубліковано 19 січ 2025

КОМЕНТАРІ • 9

  • @phongs2nhu
    @phongs2nhu 3 роки тому +1

    Could you please explain to me the difference between AWS Organizations OU vs IAM Group? Thanks in advance.

    • @carotech1973
      @carotech1973 3 роки тому +5

      An IAM Group is to place certain IAM users with a specific set of policies (permissions ) to access certain resources; i.e: EC2, S3, etc. However, AWS Organization OU's are a way to manage multiple AWS accounts and apply specific policies to the group of accounts. So, these 2 are very different things and they achieve very different results. Some organizations can have 20, 30 or more AWS accounts, so managing them is best when placed in Organizational Units, OUs to simplify management.

    • @samlaf92
      @samlaf92 3 роки тому

      @@carotech1973 But why do you need multiple accounts in the first place? Seems like you could just replace OUs with IAM user groups, as Phong was probably suggesting.

    • @RationalCreed
      @RationalCreed 3 роки тому

      @@samlaf92 If you have different organisational groups eg Finance and Data areas of the business, they have different budgets and may want to pay for different levels of support, infra etc all within their own budget constraints so makes sense to do that with their own respective accounts using their own standards.

    • @samlaf92
      @samlaf92 3 роки тому

      @@RationalCreed Totally agree. But even that you can solve by tagging every infrastructure that you spin up with its department and then look at budget spending per department, all within the confines of a single account.

    • @rohithprakash2619
      @rohithprakash2619 10 місяців тому

      @@samlaf92 that is what even I'm thinking...

  • @MindlessTurtle
    @MindlessTurtle 3 роки тому

    Are there any videos that explain how to do any of this?

    • @carotech1973
      @carotech1973 3 роки тому +1

      You need to setup an organization in your master account and then you can invite other AWS accounts to join your organization OR ... you can create new accounts that will be part of your organization. Again, this is all great when you need to manage multiple AWS accounts. Some companies have multiple accounts for billing purposes, so they can bill different departments for AWS services. Example, 1 AWS for IT, 1 for HR , 1 for Accounting, etc, etc ...

  • @richardlanglois5183
    @richardlanglois5183 5 років тому +2

    Cool!