AWS Landing Zone and AWS Control Tower help set up and govern a new, secure, multi-account AWS environment based on AWS best practices. Both consist of core accounts and resources which will implement a initial security baseline.
The following table compares the managed service (AWS Control Tower) with the solution (AWS Landing Zone).
π¨ AWS Control Tower allows existing organizations to set up a landing zone.
βAre you new two AWS?
βοΈUse AWS Control Tower
βDo you need a configurable landing zone with full customization and control over every part?
βοΈUse AWS Landing Zone
Member accounts could be provisioned in every region no matter where the Account Vending Machine is deployed.
β οΈYou just need to take care that your CloudFormation templates & Lambdas are available in the requested region.
AWS Control Tower could provision new Accounts (Network baseline) into the following regions: North-Virginia (us-east-1), Ohio (us-east-2), Oregon (us-west-2), Irland (eu-west-1) and Sydney (ap-southeast-2).