# AWS Control Tower Activation Day October 28th Gracias a todos por acompañarnos en este AWS Control Tower Activation Day, un día lleno de grandes aprendizajes en el que hablamos sobre la estrategia de múltiples cuentas y cómo AWS Control Tower puede ayudarlo a mantener su entorno seguro y en cumplimiento. # Por favor, complete la siguiente encuesta: [aqui](https://survey.immersionday.com/L90Ja_pGg). ## Laboratorios y materiales [![Get The slides](https://notasdofelip.s3.amazonaws.com/activationday/cover.png)](https://notasdofelip.s3.amazonaws.com/activationday/ADMex.zip) Vínculo a los laboratorios: https://controltower.aws-management.tools/ ## Agenda (Hora Central Mexico - CT) 09:00AM-09:10AM Kickoff + Introducciones 09:10AM-09:40AM Accounts Architecture Discussion (Multi Account Strategy) 09:40AM-10:20AM AWS Control Tower Overview 10:20AM-10:40AM Deep Dive into AWS Control Tower (DEMO) 10:30AM-11:00AM BreakOut (Q+A) 11:00AM - 11:15AM Life Cycle Events, Customization and Advanced Features 11:15AM - 11:30AM Trivia (2 prizes) 11:30AM - 11:40AM Labs 12:00AM - 02:00PM <!-- # --> ## Vínculos útiles: [Control Tower Getting Started Guide](https://docs.aws.amazon.com/controltower/latest/userguide/getting-started-with-control-tower.html) [AWS Secure Account Setup](https://aws.amazon.com/answers/security/aws-secure-account-setup/) [Getting Started: Follow Security Best Practices as You Configure Your AWS Resources](https://aws.amazon.com/blogs/security/getting-started-follow-security-best-practices-as-you-configure-your-aws-resources/) [Building a Scalable and Secure Multi-VPC AWS Network Infrastructure](https://d1.awsstatic.com/whitepapers/building-a-scalable-and-secure-multi-vpc-aws-network-infrastructure.pdf) [AWS Service Catalog Connector for ServiceNow](https://aws.amazon.com/blogs/aws/new-aws-service-catalog-connector-for-servicenow/) [Automating AWS Security Hub Alerts wiht AWS Control Tower lifecycle events](https://aws.amazon.com/blogs/mt/automating-aws-security-hub-alerts-with-aws-control-tower-lifecycle-events/) ### Borrar los recursos de Control Tower https://docs.aws.amazon.com/controltower/latest/userguide/walkthrough-delete.html#control-tower-cleanup-help ### Gestión automática de recursos efímeros para pruebas usando tecnología sin servidor https://aws.amazon.com/es/blogs/aws-spanish/gestion-automatica-de-recursos-efimeros-para-pruebas-usando-tecnologia-sin-servidor/ ### GuardDuty: Installing this Customization will enable GuardDuty in all AWS Control Tower managed accounts, with the Audit account acting as the default GuardDuty Master: https://github.com/aws-samples/aws-control-tower-guardduty-enabler ### AWS SSO con Azure AD: Evolution of Single Sign-on - Integrate with Azure AD with automatic user provisioning: https://aws.amazon.com/blogs/aws/the-next-evolution-in-aws-single-sign-on/ ### AWS SSO via CLI 2.0: With AWS CLI 2.0 you can easily configure one or more of your AWS CLI named profiles (https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-profiles.html) to use a role from AWS SSO https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-sso.html ### Serverless Transit Network Orchestrator (STNO) The Serverless Transit Network Orchestrator (STNO) solution adds automation to AWS Transit Gateway. This solution provides the tools necessary to automate the process of setting up and managing transit networks in distributed AWS environments. A web interface is created to help control, audit, and approve (transit) network changes. STNO supports both AWS Organizations (https://aws.amazon.com/organizations/) and standalone AWS account types. https://aws.amazon.com/solutions/implementations/serverless-transit-network-orchestrator/ ![](https://i.imgur.com/VYfYDqD.png) ### AWS Control Tower en Organizaciones existentes: AWS Control tower can how be enabled in existing Organizations: https://www.youtube.com/watch?v=y6QLFn00A3U (https://www.youtube.com/watch?v=y6QLFn00A3U&feature=youtu.be) ### Importar cuentas existentes: Enroll existing AWS accounts into AWS Control Tower (https://aws.amazon.com/pt/blogs/field-notes/enroll-existing-aws-accounts-into-aws-control-tower/) ### AWS Config Conformance Packs: You can prepare accounts to get enrolled in Control Tower, with Conformance Packs: https://docs.aws.amazon.com/config/latest/developerguide/aws-control-tower-detective-guardrails.html