How AWS Control Tower differs in AWS European Sovereign Cloud - AWS European Sovereign Cloud User Guide
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

How AWS Control Tower differs in AWS European Sovereign Cloud

This topic describes the functionality of AWS Control Tower in the AWS European Sovereign Cloud Region.

AWS Control Tower is a service that enables you to enforce and manage governance rules for security, operations, and compliance at scale across all your organizations and accounts in the AWS Cloud.

Service Differences

The following differences apply to AWS Control Tower in AWS European Sovereign Cloud:

API Permissions

The following permissions are not available in this partition:

  • controltower:DescribeManagedAccount

  • controltower:DescribeManagedOrganizationalUnit

  • controltower:ListManagedOrganizationalUnits

  • controltower:ListManagedAccounts

  • controltower:ManageOrganizationalUnit

  • controltower:DescribeRegisterOrganizationalUnitOperation

  • controltower:DescribeGuardrailForTarget

  • controltower:ListGuardrailsForTarget

  • controltower:DisableGuardrail

  • controltower:EnableGuardrail

  • controltower:DeregisterOrganizationalUnit

  • controltower:SetupLandingZone

  • controltower:PerformPreLaunchChecks

  • controltower:GetLandingZoneStatus

  • controltower:DescribeLandingZoneConfiguration

  • controltower:GetAvailableUpdates

  • controltower:GetLandingZoneDriftStatus

  • controltower:GetHomeRegion

  • controltower:DescribeGuardrail

  • controltower:ListGuardrails

Use the following permissions instead:

  • controltower:GetEnabledBaseline

  • controltower:ListEnabledBaselines

  • controltower:ResetEnabledBaseline

  • controltower:UpdateLandingZone

  • controltower:GetBaselineOperation

  • controltower:GetEnabledControl

  • controltower:ListEnabledControls

  • controltower:ResetLandingZone

  • controltower:GetLandingZoneOperation

  • controltower:CreateLandingZone

  • controltower:DeleteLandingZone

  • controltower:EnableControl

  • controltower:DisableBaseline

  • controltower:EnableBaseline

  • controltower:ListLandingZoneOperations

  • controltower:GetLandingZone

  • controltower:ListLandingZones

  • controltower:UpdateEnabledBaseline

  • controlcatalog:GetControl

  • controlcatalog:ListControls

Controls

Account Provisioning and Customization

Landing Zone

Baselines

  • IdentityCenterBaseline is not available due to the lack of IAM Identity Center integration.

  • The following baselines are not available due to the lack of AWS Backup integration:

    • BackupCentralVaultBaseline

    • BackupAdminBaseline

    • BackupBaseline

Documentation References