AWS Multi-Account Landing Zone Architecture

AWS multi-account landing zone architecture with AWS Organizations for account governance, Transit Gateway for centralized networking, shared services VPC with Directory Service, centralized logging account with CloudTrail and Config aggregation, security account with GuardDuty and Security Hub, and…

aws · architecture diagram.

About This Architecture

AWS multi-account landing zone architecture with AWS Organizations for account governance, Transit Gateway for centralized networking, shared services VPC with Directory Service, centralized logging account with CloudTrail and Config aggregation, security account with GuardDuty and Security Hub, and workload accounts with isolated VPCs. Includes SSO for federated access and Service Control Policies for guardrails. Fork this diagram on Diagrams.so to customize the account structure or add additional organizational units for your enterprise landing zone. Source: https://aws.amazon.com/architecture/

AWS Multi-Account Landing Zone Architecture

AWSCurated TemplateNetworking
0 views0 favoritesPublic

Created by

March 14, 2026

Updated

March 14, 2026 at 7:54 PM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI