Information & Communications Technology

Landing Zone Design for Multi-Account Cloud Environments

Design a multi-account cloud landing zone with a management account, organisational units, policy-based guardrails, centralised logging and a hub-and-spoke network that new workload accounts inherit automatically.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

A cloud environment that starts as a single account or subscription and grows workload by workload eventually mixes production and test systems, gives every team standing access to billing and identity settings, and leaves security teams unable to answer basic questions about what exists. A landing zone solves this before it becomes a problem: a management account and a hierarchy of organisational units, each with policy-based guardrails that block or flag dangerous actions before they happen, a centralised logging account that collects activity from every member account, and a shared services account for networking, identity and DNS. This course designs each of these components and the hub-and-spoke network topology that connects them, then automates account creation itself through an account factory so a new workload account arrives pre-configured with logging, guardrails and network connectivity rather than waiting for manual setup. Participants also build a tagging and cost allocation standard, identity federation to a central directory, and a compliance baseline aligned to a recognised benchmark, finishing with a landing zone that scales to many teams without each one reinventing account governance.

Expected Learning Outcomes

01

Design a management account and organisational unit hierarchy that reflects business structure.

02

Define policy-based guardrails that prevent or detect actions outside agreed security boundaries.

03

Build a centralised logging account that captures activity from every member account.

04

Design a shared services account providing networking, identity and DNS to workload accounts.

05

Automate new account provisioning through an account factory with guardrails pre-applied.

06

Establish a tagging and cost allocation standard that supports chargeback and budget alerts.

07

Align a landing zone compliance baseline to a recognised security benchmark and audit it.

Who Should Attend

01

Cloud architects designing account structure for a growing cloud estate.

02

Platform engineering teams building a landing zone for internal customers.

03

Security engineers defining guardrails and compliance baselines for cloud accounts.

04

FinOps and cost management staff needing consistent tagging across accounts.

05

IT leaders consolidating scattered cloud accounts under central governance.

06

Consultants delivering landing zone projects for enterprise cloud clients.

Course Modules

Select any module to see its sessions and points.

01

Landing Zone Foundations and Account Hierarchy

2 sessions · 8 points

Session 1Management Accounts and Organisational Units

  • Design a management account structure separate from any account running workloads.
  • Group accounts into organisational units that reflect business unit or environment boundaries.
  • Decide which accounts are shared services, which are workload, and which are sandboxes.
  • Document an account hierarchy that a new business unit can be onboarded into predictably.

Session 2Guardrails and Preventive and Detective Controls

  • Design preventive guardrails that block actions such as disabling logging or leaving a region.
  • Design detective guardrails that flag risky configuration without blocking legitimate work.
  • Apply guardrails at the organisational unit level so new accounts inherit them automatically.
  • Test guardrail behaviour against both compliant and deliberately non-compliant actions.
02

Centralised Logging, Identity and Networking

2 sessions · 8 points

Session 1Centralised Logging and Security Tooling

  • Route activity logs, configuration history and security findings to a central logging account.
  • Restrict write access to the logging account so logs cannot be altered from a workload account.
  • Set retention periods for logs that satisfy both operational and compliance needs.
  • Design alerting that routes security findings to the team responsible for each account.

Session 2Identity Federation and Shared Networking

  • Federate account access to a central identity provider instead of per-account local users.
  • Design role-based access so permissions match job function rather than account ownership.
  • Build a hub-and-spoke network topology connecting workload accounts to shared services.
  • Centralise DNS resolution and network egress through the shared services account.
03

Account Vending and Automation

2 sessions · 8 points

Session 1Building an Account Factory

  • Define a standard account template covering baseline networking, logging and guardrails.
  • Automate account creation so a requested account is provisioned in a repeatable sequence.
  • Version the account factory templates so improvements reach new accounts automatically.
  • Test the account factory end to end before it is offered to internal teams.

Session 2Tagging, Cost Allocation and Budgeting

  • Define a mandatory tagging standard covering owner, cost centre and environment.
  • Enforce tagging compliance through guardrails rather than relying on manual discipline.
  • Build cost allocation reporting that attributes spend back to the responsible team.
  • Configure budget alerts that notify account owners before spend exceeds agreed limits.
04

Compliance, Drift and Ongoing Governance

2 sessions · 8 points

Session 1Compliance Baselines and Auditing

  • Map landing zone controls to a recognised security benchmark such as the CIS benchmark.
  • Run periodic compliance audits that check accounts against the agreed baseline.
  • Produce audit evidence that demonstrates guardrails have been continuously enforced.
  • Handle exceptions where a workload genuinely needs to deviate from the baseline.

Session 2Drift Detection and Landing Zone Evolution

  • Detect configuration drift between an account's actual state and its intended baseline.
  • Plan safe rollout of landing zone changes across existing accounts without downtime.
  • Version landing zone infrastructure-as-code templates and review changes before release.
  • Review landing zone effectiveness periodically as new services and teams are added.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course