SlideShare a Scribd company logo
Sandbox of company by AWS Control Tower
Create a sandbox of company costs with AWS Control
Tower and benefit from continuous external output
Mitsuhiro Yamashita(Trainocate) - AAI Champion
ATP Award Best Instructor 2018,2019,2020
2021 APN AWS Top Engineers 100
AWS Sandbox of company ($570/Month)
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
AWS Sandbox of company ($570/Month)
Mast
er
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
https://www.yamamanx.com/aws-control-tower-landing-zone/
OU-Tool
Test
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://www.yamamanx.com/microsoft-teams-incoming-webhooks-aws-lambda-feedly/
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
{
"Statement": [
{
"Effect": "Deny",
"Action": [
"route53domains:RegisterDomain",
"ec2:PurchaseReserved*",
"glacier:CompleteVaultLock",
"snowball:Create*",
"savingsplan:*"
"aws-marketplace:Subscribe",
"rds:PurchaseReserved*",
etc ,,,,,,,,
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
{
"Statement": [
{
"Effect": "Deny",
"Action": [
"route53domains:RegisterDomain",
"ec2:PurchaseReserved*",
"glacier:CompleteVaultLock",
"snowball:Create*",
"savingsplan:*"
"aws-marketplace:Subscribe",
"rds:PurchaseReserved*",
etc ,,,,,,,,
https://www.yamamanx.com/scp-policy/
IAM User + Role, Cross account access
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
IAM User + Role, Cross account access
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
https://www.yamamanx.com/iam-user-password-mfa/
AWS SSO + Azure AD
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://youtu.be/_kzJ660gEuo
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://www.youtube.com/watch?v=kuXKLgx8Bpw
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://blog.trainocate.co.jp/blog/199
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://blog.trainocate.co.jp/blog/rekognition_profile_022
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://blog.trainocate.co.jp/blog/qaforma-2020_022
AWS Sandbox of company
Master
OU-AAI
AAI a
AAI b
AAI c
AAI d
AAI e
OU-Test
Test
OU-Security
Log
Archive
Audit
AWS Control Tower
AWS Organizations
OU-Tool
Test
https://blog.trainocate.co.jp/blog/zoom-api-tool_022
My Life Cycle
Input Test
Recording
(Blog)
Prototyping
Training
Demo
Document
Writing
Adovocate
OnStage

More Related Content

PDF
AWS Black Belt Online Seminar - Amazon Lightsail
PDF
20201111 AWS Black Belt Online Seminar AWS CodeStar & AWS CodePipeline
PDF
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
PDF
AWS Black Belt Online Seminar 2017 AWSへのネットワーク接続とAWS上のネットワーク内部設計
PDF
20200721 AWS Black Belt Online Seminar AWS App Mesh
PDF
AWS Black Belt Tech シリーズ 2015 - AWS Data Pipeline
PDF
20190226 AWS Black Belt Online Seminar Amazon WorkSpaces
PDF
AWS Black Belt Online Seminar 2016 Amazon EMR
AWS Black Belt Online Seminar - Amazon Lightsail
20201111 AWS Black Belt Online Seminar AWS CodeStar & AWS CodePipeline
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
AWS Black Belt Online Seminar 2017 AWSへのネットワーク接続とAWS上のネットワーク内部設計
20200721 AWS Black Belt Online Seminar AWS App Mesh
AWS Black Belt Tech シリーズ 2015 - AWS Data Pipeline
20190226 AWS Black Belt Online Seminar Amazon WorkSpaces
AWS Black Belt Online Seminar 2016 Amazon EMR

What's hot (20)

PDF
AWS Black Belt Online Seminar 2017 Amazon Pinpoint で始めるモバイルアプリのグロースハック
PPTX
AWSを利用したA社システムの提案
PDF
20190911 AWS Black Belt Online Seminar AWS Batch
PDF
아마존의 관리형 게임 플랫폼 활용하기: GameLift (Deep Dive) :: 구승모 솔루션즈 아키텍트 :: Gaming on AWS ...
PDF
Kinesis + Elasticsearchでつくるさいきょうのログ分析基盤
PPTX
Amazon WorkSpaces導入のコツと活用事例
PDF
AWS Black Belt Online Seminar 2017 AWS WAF
PDF
20191120 AWS Black Belt Online Seminar Amazon Managed Streaming for Apache Ka...
PDF
20180717 AWS Black Belt Online Seminar AWS大阪ローカルリージョンの活用とAWSで実現するDisaster Rec...
PDF
20200728 AWS Black Belt Online Seminar What's New in Serverless
PDF
20201118 AWS Black Belt Online Seminar 形で考えるサーバーレス設計 サーバーレスユースケースパターン解説
PDF
AWS IoTにおけるデバイスへの認証情報のプロビジョニング
PDF
20191016 AWS Black Belt Online Seminar Amazon Route 53 Resolver
PDF
今改めて学ぶ Microsoft Azure 基礎知識
PDF
20180322 AWS Black Belt Online Seminar AWS Snowball Edge
PDF
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
PDF
20180509 AWS Black Belt Online Seminar Amazon GuardDuty
PDF
20200708サーバーレスでのAPI管理の考え方
PDF
20191001 AWS Black Belt Online Seminar AWS Lake Formation
PDF
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
AWS Black Belt Online Seminar 2017 Amazon Pinpoint で始めるモバイルアプリのグロースハック
AWSを利用したA社システムの提案
20190911 AWS Black Belt Online Seminar AWS Batch
아마존의 관리형 게임 플랫폼 활용하기: GameLift (Deep Dive) :: 구승모 솔루션즈 아키텍트 :: Gaming on AWS ...
Kinesis + Elasticsearchでつくるさいきょうのログ分析基盤
Amazon WorkSpaces導入のコツと活用事例
AWS Black Belt Online Seminar 2017 AWS WAF
20191120 AWS Black Belt Online Seminar Amazon Managed Streaming for Apache Ka...
20180717 AWS Black Belt Online Seminar AWS大阪ローカルリージョンの活用とAWSで実現するDisaster Rec...
20200728 AWS Black Belt Online Seminar What's New in Serverless
20201118 AWS Black Belt Online Seminar 形で考えるサーバーレス設計 サーバーレスユースケースパターン解説
AWS IoTにおけるデバイスへの認証情報のプロビジョニング
20191016 AWS Black Belt Online Seminar Amazon Route 53 Resolver
今改めて学ぶ Microsoft Azure 基礎知識
20180322 AWS Black Belt Online Seminar AWS Snowball Edge
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
20180509 AWS Black Belt Online Seminar Amazon GuardDuty
20200708サーバーレスでのAPI管理の考え方
20191001 AWS Black Belt Online Seminar AWS Lake Formation
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
Ad

More from Mitsuhiro Yamashita (20)

PPTX
AWSセキュリティ新機能と共に進化した My Individual blog (私の個人ブログ) since 2014
PPTX
My Individual Output
PPTX
46でγ-GTP 生まれて初の基準値に
PPTX
アウトプットはスキルアップもするしトクもする
PPTX
ブログを大阪リージョンに移行して東京リージョンをDRサイトにしています。その理由とRTO/RPOそしてコスト。
PPTX
AWSの勉強は試して試して楽しんで (AWS認定DVA本書きました)
PPTX
AWS関連のブログを書いてて山ほど得したこと
PPTX
Twilioと山下と学び
PPTX
GAS + SaaS時々 AWSで自動化
PPTX
怒涛のAWS入門! クラウドプラクティショナー! 知ってました? あなた、クラウドプラクティショナーなんですよ。
PPTX
ヤマムギとは
PPTX
AWS認定クラウドプラクティショナー 書くときに意識してたこととか
PPTX
AAIから君へ
PPTX
AZ障害を想定したブログのマイグレーション
PPTX
Amazon Connectで到着報告を自動化
PPTX
kintoneとAmazon Connectで日直の自動化など
PPTX
AWSへのシステム移行に伴う クラウドマインドへの移行
PPTX
Slack,Teams,LINE botの作り方の違いとか
PPTX
Slack,Teams,LINE botの作り方の違いとか
PPTX
JAWS-UGのご紹介
AWSセキュリティ新機能と共に進化した My Individual blog (私の個人ブログ) since 2014
My Individual Output
46でγ-GTP 生まれて初の基準値に
アウトプットはスキルアップもするしトクもする
ブログを大阪リージョンに移行して東京リージョンをDRサイトにしています。その理由とRTO/RPOそしてコスト。
AWSの勉強は試して試して楽しんで (AWS認定DVA本書きました)
AWS関連のブログを書いてて山ほど得したこと
Twilioと山下と学び
GAS + SaaS時々 AWSで自動化
怒涛のAWS入門! クラウドプラクティショナー! 知ってました? あなた、クラウドプラクティショナーなんですよ。
ヤマムギとは
AWS認定クラウドプラクティショナー 書くときに意識してたこととか
AAIから君へ
AZ障害を想定したブログのマイグレーション
Amazon Connectで到着報告を自動化
kintoneとAmazon Connectで日直の自動化など
AWSへのシステム移行に伴う クラウドマインドへの移行
Slack,Teams,LINE botの作り方の違いとか
Slack,Teams,LINE botの作り方の違いとか
JAWS-UGのご紹介
Ad

Recently uploaded (20)

PDF
Geotechnical Engineering, Soil mechanics- Soil Testing.pdf
PDF
Embodied AI: Ushering in the Next Era of Intelligent Systems
PPT
Chapter 6 Design in software Engineeing.ppt
PDF
July 2025 - Top 10 Read Articles in International Journal of Software Enginee...
DOCX
573137875-Attendance-Management-System-original
PDF
Model Code of Practice - Construction Work - 21102022 .pdf
PPTX
UNIT-1 - COAL BASED THERMAL POWER PLANTS
PPTX
bas. eng. economics group 4 presentation 1.pptx
PDF
Arduino robotics embedded978-1-4302-3184-4.pdf
PPTX
The-Looming-Shadow-How-AI-Poses-Dangers-to-Humanity.pptx
PPTX
Road Safety tips for School Kids by a k maurya.pptx
PDF
Operating System & Kernel Study Guide-1 - converted.pdf
PPTX
web development for engineering and engineering
PDF
SM_6th-Sem__Cse_Internet-of-Things.pdf IOT
PDF
algorithms-16-00088-v2hghjjnjnhhhnnjhj.pdf
PDF
Evaluating the Democratization of the Turkish Armed Forces from a Normative P...
PPTX
Unit 5 BSP.pptxytrrftyyydfyujfttyczcgvcd
PPTX
MCN 401 KTU-2019-PPE KITS-MODULE 2.pptx
PPTX
CH1 Production IntroductoryConcepts.pptx
Geotechnical Engineering, Soil mechanics- Soil Testing.pdf
Embodied AI: Ushering in the Next Era of Intelligent Systems
Chapter 6 Design in software Engineeing.ppt
July 2025 - Top 10 Read Articles in International Journal of Software Enginee...
573137875-Attendance-Management-System-original
Model Code of Practice - Construction Work - 21102022 .pdf
UNIT-1 - COAL BASED THERMAL POWER PLANTS
bas. eng. economics group 4 presentation 1.pptx
Arduino robotics embedded978-1-4302-3184-4.pdf
The-Looming-Shadow-How-AI-Poses-Dangers-to-Humanity.pptx
Road Safety tips for School Kids by a k maurya.pptx
Operating System & Kernel Study Guide-1 - converted.pdf
web development for engineering and engineering
SM_6th-Sem__Cse_Internet-of-Things.pdf IOT
algorithms-16-00088-v2hghjjnjnhhhnnjhj.pdf
Evaluating the Democratization of the Turkish Armed Forces from a Normative P...
Unit 5 BSP.pptxytrrftyyydfyujfttyczcgvcd
MCN 401 KTU-2019-PPE KITS-MODULE 2.pptx
CH1 Production IntroductoryConcepts.pptx

Create a sandbox of company costs with AWS Control Tower and benefit from continuous external output

  • 1. Sandbox of company by AWS Control Tower Create a sandbox of company costs with AWS Control Tower and benefit from continuous external output
  • 2. Mitsuhiro Yamashita(Trainocate) - AAI Champion ATP Award Best Instructor 2018,2019,2020 2021 APN AWS Top Engineers 100
  • 3. AWS Sandbox of company ($570/Month) Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test
  • 4. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test
  • 5. AWS Sandbox of company ($570/Month) Mast er OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations https://www.yamamanx.com/aws-control-tower-landing-zone/ OU-Tool Test
  • 6. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test
  • 7. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://www.yamamanx.com/microsoft-teams-incoming-webhooks-aws-lambda-feedly/
  • 8. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test { "Statement": [ { "Effect": "Deny", "Action": [ "route53domains:RegisterDomain", "ec2:PurchaseReserved*", "glacier:CompleteVaultLock", "snowball:Create*", "savingsplan:*" "aws-marketplace:Subscribe", "rds:PurchaseReserved*", etc ,,,,,,,,
  • 9. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test { "Statement": [ { "Effect": "Deny", "Action": [ "route53domains:RegisterDomain", "ec2:PurchaseReserved*", "glacier:CompleteVaultLock", "snowball:Create*", "savingsplan:*" "aws-marketplace:Subscribe", "rds:PurchaseReserved*", etc ,,,,,,,, https://www.yamamanx.com/scp-policy/
  • 10. IAM User + Role, Cross account access Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations
  • 11. IAM User + Role, Cross account access Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations https://www.yamamanx.com/iam-user-password-mfa/
  • 12. AWS SSO + Azure AD Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations
  • 13. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://youtu.be/_kzJ660gEuo
  • 14. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://www.youtube.com/watch?v=kuXKLgx8Bpw
  • 15. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://blog.trainocate.co.jp/blog/199
  • 16. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://blog.trainocate.co.jp/blog/rekognition_profile_022
  • 17. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://blog.trainocate.co.jp/blog/qaforma-2020_022
  • 18. AWS Sandbox of company Master OU-AAI AAI a AAI b AAI c AAI d AAI e OU-Test Test OU-Security Log Archive Audit AWS Control Tower AWS Organizations OU-Tool Test https://blog.trainocate.co.jp/blog/zoom-api-tool_022
  • 19. My Life Cycle Input Test Recording (Blog) Prototyping Training Demo Document Writing Adovocate OnStage