# AWS Control Tower Activation Gracias a todos por acompañarnos en este AWS Control Tower Activation Day, un día lleno de grandes aprendizajes en el que hablamos sobre la estrategia de múltiples cuentas y cómo AWS Control Tower puede ayudarlo a mantener su entorno seguro y en cumplimiento. ## Sala Sala de conferencia principal --> https://chime.aws/3915079356 ## Encuesta de Satisfacción Por favor complete la encuesta: [aqui](https://survey.immersionday.com/RdJLU4V7R). ## 27 de Agosto, 2021 | 9:00AM - 2:00PM Horario de México - 09:00AM – 09:20AM Kick-Off + Introductions - 09:20AM – 09:50AM MultiAccount Discussion - 09:50AM – 10:00AM Break - 10:00AM – 11:00AM AWS Control Tower Overview - 11:00AM – 11:30AM Deep Dive into AWS Control Tower (Demo) - 11:30AM – 11:40AM Break - 11:40AM – 12:00PM Life Cycle Events, Customization (*Session)* - 12:00PM – 12:30PM Q&A - 12:30PM – 12:40PM Kahoot - 12:40PM – 12:50PM Labs: Introduction and Preparations (BYOA) - Compartir ID Read Only - 12:50AM – 2:00PM Labs: (*Proctoring*) ## Trivia Premio de Echo Dot 3era generación al ganador!!! https://kahoot.it/ Game pin: TBD ## Labs Vínculo a los laboratorios: https://controltower.aws-management.tools/ ## Vínculos útiles: Pueden descargar los materiales [aqui](https://renbrave-aws-docs.s3.amazonaws.com/Control+Tower+Decks.zip). [Guia de seguridad de multiples cuentas](https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/architecture.html) [Grabación del evento (Videos)](https://benfelip-sharing.s3.amazonaws.com/AD-210827/AD-Video-27-08-2021.zip) [Network firewall centralizado](https://aws.amazon.com/pt/blogs/mt/scale-multi-account-architecture-aws-network-firewall-and-aws-control-tower/) [Control Tower Getting Started Guide](https://docs.aws.amazon.com/controltower/latest/userguide/getting-started-with-control-tower.html) [AWS Secure Account Setup](https://aws.amazon.com/answers/security/aws-secure-account-setup/) [Getting Started: Follow Security Best Practices as You Configure Your AWS Resources](https://aws.amazon.com/blogs/security/getting-started-follow-security-best-practices-as-you-configure-your-aws-resources/) [Building a Scalable and Secure Multi-VPC AWS Network Infrastructure](https://d1.awsstatic.com/whitepapers/building-a-scalable-and-secure-multi-vpc-aws-network-infrastructure.pdf) [AWS Service Catalog Connector for ServiceNow](https://aws.amazon.com/blogs/aws/new-aws-service-catalog-connector-for-servicenow/) [Automating AWS Security Hub Alerts wiht AWS Control Tower lifecycle events](https://aws.amazon.com/blogs/mt/automating-aws-security-hub-alerts-with-aws-control-tower-lifecycle-events/) ### Estrategia de multiples cuentas en AWS, cuando usar cada cual https://aws.amazon.com/es/blogs/aws-spanish/preparese-para-escalar-en-la-nube-estrategia-de-multiples-cuentas/ ### Gestión automática de recursos efímeros para pruebas usando tecnología sin servidor https://aws.amazon.com/es/blogs/aws-spanish/gestion-automatica-de-recursos-efimeros-para-pruebas-usando-tecnologia-sin-servidor/ ### Installing this Customization will enable GuardDuty in all AWS Control Tower managed accounts, with the Audit account acting as the default GuardDuty Master: https://github.com/aws-samples/aws-control-tower-guardduty-enabler ### AWS SSO con Azure AD: Evolution of Single Sign-on - Integrate with Azure AD with automatic user provisioning: https://aws.amazon.com/blogs/aws/the-next-evolution-in-aws-single-sign-on/ ### AWS SSO via CLI 2.0: With AWS CLI 2.0 you can easily configure one or more of your AWS CLI named profiles (https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-profiles.html) to use a role from AWS SSO https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-sso.html ### Serverless Transit Network Orchestrator (STNO) The Serverless Transit Network Orchestrator (STNO) solution adds automation to AWS Transit Gateway. This solution provides the tools necessary to automate the process of setting up and managing transit networks in distributed AWS environments. A web interface is created to help control, audit, and approve (transit) network changes. STNO supports both AWS Organizations (https://aws.amazon.com/organizations/) and standalone AWS account types. https://aws.amazon.com/solutions/implementations/serverless-transit-network-orchestrator/ ![](https://i.imgur.com/VYfYDqD.png) ### AWS Control Tower en Organizaciones existentes: AWS Control tower can how be enabled in existing Organizations: https://www.youtube.com/watch?v=y6QLFn00A3U (https://www.youtube.com/watch?v=y6QLFn00A3U&feature=youtu.be) ### AWS Config Conformance Packs: You can prepare accounts to get enrolled in Control Tower, with Conformance Packs: https://docs.aws.amazon.com/config/latest/developerguide/aws-control-tower-detective-guardrails.html