SlideShare a Scribd company logo
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Ali Asgar Juzer
Sr. Advisory Consultant, Professional Services
Amazon Web Services
Landing Zones: Creating a
Foundation for Your AWS Migrations
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Session Agenda
1. Definition of the Problem
2. Landing Zone Concept
3. Components of a Landing Zone
4. AWS Best Practices & Tips for Building a Landing Zone
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Definition of the Problem
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
meets the organization’s
security and auditing
requirements
ready to support highly
available and scalable
workloads
configurable to
support evolving business
requirements
What do you need
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Landing Zone Concept
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Landing
Zone
What is a Landing Zone
Multi-Account AWS Environment
Based on AWS Best Practices
Set of Architecture Patterns
For Shared Core Services
Adaptable Foundation
With Governance Guardrails
Automation Driven
Versioned Infrastructure
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Logging Configuration Image
Migrate
Iterate
Operate &
Optimize
Start Accounts
End User
Interaction
AutomationService
Catalog
Domains Direct
Connect
Central
Services
Access Identities Federation
Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
Building a Landing Zone
Business
Needs
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Landing Zone Components
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Start Accounts Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Account Structure
Billing visibility
Environment isolation
Small blast radius
Shared Core services
Centralized logs
Governance at Scale
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Start Accounts Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Non-overlapping
IP range
VPC Design
Logging and
Monitoring
VPN / AWS
Direct
Connect
Subnet Design
Access Control Lists &
Security Groups
Network Design
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Network Design
VPN/Direct Connect
VPC Peering
DNS Domains Ingress/Egress Points
Bastion Hosts
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Start Accounts Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security
CloudWatch Metrics &
Alarms
CloudTrail Logs for
Auditing
VPC Flow Logs for
Network Insights
AMI Factory for
Hardened OS Images
Amazon GuardDuty for
Threat Detection
AWS Config Rules for
Dynamic Compliance
and more…
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Start Accounts Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Identity & Access Management
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Corporate Data Center
Browser interface
Identity
Store
AD Group
Identity and
authentication
AWS Accounts
Identity & Access Management
Mapping to specific
IAM roles with
access policies
Example: Federation with AD
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Start Accounts Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cloud
consumers
Browse
products
2
5
Notifications and
outputs
Notifications
and outputs
5
4
Deploy
Administrator
3 Select version,
Provision
product,
configure
parameters
Portfolio
Cloud Consumption Model
Example: AWS Service Catalog
1 Maintain Products
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Start Accounts Network Security
Identity &
Access
Cloud
Users
What’s
Next ?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Build, Operate and Optimize
AWS Managed
Services
AWS Managed Services
Provider Partners
Build & Manage
Your Own
Infrastructure Operations
Management for the
Enterprise by AWS
Next Gen Managed Services
Providers with 3rd Party
Audits
In-house Capabilities to Run
& Operate at Scale
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Tips to Get Started
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Best Practices & Tips
LZ
1. Automate Everything
2. Start Small, Develop Fast, Iterate Frequently
3. Collaborate & Improve
4. Assess Build vs. Buy Decisions
5. Learn & Seek from the Experts
6. Think Holistic - Business, Governance, People, Platform,
Security & Operations
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What Did We Cover in This Session
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
meets the organization’s
security and auditing
requirements
ready to support highly
available and scalable
workloads
configurable to
support evolving business
requirements
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Landing
Zone
Multi-Account AWS Environment
Based on AWS Best Practices
Set of Architecture Patterns
For Shared Core Services
Adaptable Foundation
With Governance Guardrails
Automation Driven
Versioned Infrastructure
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Managed
Services
AWS Managed Services
Provider Partners
Build & Manage
Your Own
Infrastructure Operations
Management for the
Enterprise by AWS
Next Gen Managed Services
Providers with 3rd Party
Audits
In-house Capabilities to Run
& Operate at Scale
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you!
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Please complete the session survey in
the summit mobile app.

More Related Content

PDF
Busting the Myths to AWS Cloud Adoption_Liam Caskie
PPTX
Hybrid Cloud on AWS: Foundational Layers and AWS Services
PPTX
DevOps, CI/CD, cost management, and security on AWS
PPTX
Building a Hybrid Cloud Architecture Utilizing AWS Landing Zones
PPTX
Hybrid Cloud on AWS - Introduction and Art of the Possible
PPTX
Cloud Migration, Application Modernization, and Security
PPTX
Deep dive - AWS security by design
PPTX
Adopting AWS in your organization - ITPalooza 2015
Busting the Myths to AWS Cloud Adoption_Liam Caskie
Hybrid Cloud on AWS: Foundational Layers and AWS Services
DevOps, CI/CD, cost management, and security on AWS
Building a Hybrid Cloud Architecture Utilizing AWS Landing Zones
Hybrid Cloud on AWS - Introduction and Art of the Possible
Cloud Migration, Application Modernization, and Security
Deep dive - AWS security by design
Adopting AWS in your organization - ITPalooza 2015

Similar to Landing zones: Creating a Foundation for Your AWS Migrations (20)

PDF
엔터프라이즈를 위한 하이브리드 클라우드 및 보안 관리
PDF
AWS Architecture Fundamentals - Houston
PPTX
Building Bulletproof Infrastructure on AWS
PDF
Securing Your Customers Data From Day One
PDF
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
PPTX
Cloudifying your Security Operations on AWS
PPTX
AWS 101 - An Introduction to the Amazon Cloud
PPTX
AWS Landing Zone - Architecting Security and Governance.pptx
PPTX
Pitt Immersion Day- Module 1
PDF
Segurança de Ponta a Ponta na AWS
PDF
DevopsDays Geneva 2020 - Compliance & Governance as Code
PPTX
Private Equity Value Creation Carve Outs, Divestitures and mergers
PDF
Hybrid cloud for financial sector :: Felix Candelario :: AWS Finance Seminar
PPTX
Being Well Architected in the Cloud (Updated)
PPTX
AWS Initiate - Landing Zone: Como saber se sua base está preparada
PDF
Aws Architecture Fundamentals
PPTX
Managing Security on AWS
PDF
Security in the cloud
PDF
Being Well Architected in the Cloud
PDF
AWS STARTUP DAY 2018 I Securing Your Customer Data From Day One
엔터프라이즈를 위한 하이브리드 클라우드 및 보안 관리
AWS Architecture Fundamentals - Houston
Building Bulletproof Infrastructure on AWS
Securing Your Customers Data From Day One
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
Cloudifying your Security Operations on AWS
AWS 101 - An Introduction to the Amazon Cloud
AWS Landing Zone - Architecting Security and Governance.pptx
Pitt Immersion Day- Module 1
Segurança de Ponta a Ponta na AWS
DevopsDays Geneva 2020 - Compliance & Governance as Code
Private Equity Value Creation Carve Outs, Divestitures and mergers
Hybrid cloud for financial sector :: Felix Candelario :: AWS Finance Seminar
Being Well Architected in the Cloud (Updated)
AWS Initiate - Landing Zone: Como saber se sua base está preparada
Aws Architecture Fundamentals
Managing Security on AWS
Security in the cloud
Being Well Architected in the Cloud
AWS STARTUP DAY 2018 I Securing Your Customer Data From Day One
Ad

Recently uploaded (20)

PDF
Approach and Philosophy of On baking technology
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Spectroscopy.pptx food analysis technology
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Cloud computing and distributed systems.
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Big Data Technologies - Introduction.pptx
PDF
cuic standard and advanced reporting.pdf
PPTX
A Presentation on Artificial Intelligence
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Empathic Computing: Creating Shared Understanding
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Encapsulation theory and applications.pdf
Approach and Philosophy of On baking technology
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Dropbox Q2 2025 Financial Results & Investor Presentation
Spectroscopy.pptx food analysis technology
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Cloud computing and distributed systems.
NewMind AI Weekly Chronicles - August'25-Week II
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Spectral efficient network and resource selection model in 5G networks
Big Data Technologies - Introduction.pptx
cuic standard and advanced reporting.pdf
A Presentation on Artificial Intelligence
“AI and Expert System Decision Support & Business Intelligence Systems”
Chapter 3 Spatial Domain Image Processing.pdf
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Empathic Computing: Creating Shared Understanding
sap open course for s4hana steps from ECC to s4
Encapsulation theory and applications.pdf
Ad

Landing zones: Creating a Foundation for Your AWS Migrations

  • 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Ali Asgar Juzer Sr. Advisory Consultant, Professional Services Amazon Web Services Landing Zones: Creating a Foundation for Your AWS Migrations
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Session Agenda 1. Definition of the Problem 2. Landing Zone Concept 3. Components of a Landing Zone 4. AWS Best Practices & Tips for Building a Landing Zone
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Definition of the Problem
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. meets the organization’s security and auditing requirements ready to support highly available and scalable workloads configurable to support evolving business requirements What do you need
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Landing Zone Concept
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Landing Zone What is a Landing Zone Multi-Account AWS Environment Based on AWS Best Practices Set of Architecture Patterns For Shared Core Services Adaptable Foundation With Governance Guardrails Automation Driven Versioned Infrastructure
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Logging Configuration Image Migrate Iterate Operate & Optimize Start Accounts End User Interaction AutomationService Catalog Domains Direct Connect Central Services Access Identities Federation Network Security Identity & Access Cloud Users What’s Next ? Building a Landing Zone Business Needs
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Landing Zone Components
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Start Accounts Network Security Identity & Access Cloud Users What’s Next ?
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Account Structure Billing visibility Environment isolation Small blast radius Shared Core services Centralized logs Governance at Scale
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Start Accounts Network Security Identity & Access Cloud Users What’s Next ?
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Non-overlapping IP range VPC Design Logging and Monitoring VPN / AWS Direct Connect Subnet Design Access Control Lists & Security Groups Network Design
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Network Design VPN/Direct Connect VPC Peering DNS Domains Ingress/Egress Points Bastion Hosts
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Start Accounts Network Security Identity & Access Cloud Users What’s Next ?
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Security CloudWatch Metrics & Alarms CloudTrail Logs for Auditing VPC Flow Logs for Network Insights AMI Factory for Hardened OS Images Amazon GuardDuty for Threat Detection AWS Config Rules for Dynamic Compliance and more…
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Start Accounts Network Security Identity & Access Cloud Users What’s Next ?
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Identity & Access Management
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Corporate Data Center Browser interface Identity Store AD Group Identity and authentication AWS Accounts Identity & Access Management Mapping to specific IAM roles with access policies Example: Federation with AD
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Start Accounts Network Security Identity & Access Cloud Users What’s Next ?
  • 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Cloud consumers Browse products 2 5 Notifications and outputs Notifications and outputs 5 4 Deploy Administrator 3 Select version, Provision product, configure parameters Portfolio Cloud Consumption Model Example: AWS Service Catalog 1 Maintain Products
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Start Accounts Network Security Identity & Access Cloud Users What’s Next ?
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Build, Operate and Optimize AWS Managed Services AWS Managed Services Provider Partners Build & Manage Your Own Infrastructure Operations Management for the Enterprise by AWS Next Gen Managed Services Providers with 3rd Party Audits In-house Capabilities to Run & Operate at Scale
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Tips to Get Started
  • 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Best Practices & Tips LZ 1. Automate Everything 2. Start Small, Develop Fast, Iterate Frequently 3. Collaborate & Improve 4. Assess Build vs. Buy Decisions 5. Learn & Seek from the Experts 6. Think Holistic - Business, Governance, People, Platform, Security & Operations
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What Did We Cover in This Session © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. meets the organization’s security and auditing requirements ready to support highly available and scalable workloads configurable to support evolving business requirements © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Landing Zone Multi-Account AWS Environment Based on AWS Best Practices Set of Architecture Patterns For Shared Core Services Adaptable Foundation With Governance Guardrails Automation Driven Versioned Infrastructure © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Managed Services AWS Managed Services Provider Partners Build & Manage Your Own Infrastructure Operations Management for the Enterprise by AWS Next Gen Managed Services Providers with 3rd Party Audits In-house Capabilities to Run & Operate at Scale
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Thank you!
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Please complete the session survey in the summit mobile app.

Editor's Notes

  • #18: Key Considerations