Enterprise Best Practice: Single Landing Zone Architecture for Multi-Project Master Accounts - Huawei Cloud
Executive Summary & Core Architectural Principle Core Principle: "Decouple Financial Billing from Governance & Security, Centralize Organizational Control." In enterprises with multiple projects, each project often maintains its own Project Master Account to handle independent billing, invoicing, and negotiated commercial discounts. However, Security, Network, and Audit teams must maintain a…
The Enterprise Architecture for Multi-Project Master Accounts on Huawei Cloud emphasizes decoupling financial billing from governance and security. Each project ideally maintains its own Project Master Account for independent billing and invoicing. However, security, network, and audit teams require a single, consolidated operational boundary. Avoid setting up individual Landing Zones in Project Master Accounts as it leads to fragmented security, scattered audit logs, and hindered centralized threat detection.
Instead, deploy a single, enterprise-wide Landing Zone using an independent Management Account. Security and audit teams operate centrally within this Landing Zone. Project Master Accounts join as member accounts within specific Workloads Organizational Units. This preserves their independent billing and contract status without compromising security.
To implement, first provision an independent Governance Management Account with a dedicated email address. Designate this account as the Organizations Management Account. Next, set up the Landing Zone and create a Central Audit Account. The Security/Audit team will use this account to monitor compliance and respond to security alerts. Finally, invite Project Master Accounts into the Landing Zone. This does not alter financial relationships but allows centralized auditing and control across all projects.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.