AWS Multi-Account Landing Zone Architecture — AWS architecture diagram

About This Architecture

AWS multi-account landing zone architecture with AWS Organizations for account governance, Transit Gateway for centralized networking, shared services VPC with Directory Service, centralized logging account with CloudTrail and Config aggregation, security account with GuardDuty and Security Hub, and workload accounts with isolated VPCs. Includes SSO for federated access and Service Control Policies for guardrails. Fork this diagram on Diagrams.so to customize the account structure or add additional organizational units for your enterprise landing zone. Source: https://aws.amazon.com/architecture/

AWS Multi-Account Landing Zone Architecture

AWSCurated TemplateNetworking
34 views0 favoritesPublic

Created by

March 14, 2026

Updated

August 18, 2026 at 5:05 PM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI

AI-generated. Verify before production use. Learn more

Report this diagram