AWS Config vs. AWS Control Tower

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
AWS Config
Score 7.0 out of 10
N/A
Amazon Web Services offers AWS Config, a service that provides monitoring and assessment of AWS resource configurations to support compliance auditing, change management and troubleshooting, with resource histories and comparison of historical configurations against planned configurations.N/A
AWS Control Tower
Score 8.1 out of 10
N/A
The vendor presents AWS Control Tower as the easiest way to set up and govern a new, secure multi-account AWS environment. With AWS Control Tower, builders can provision new AWS accounts in a few clicks, while knowing new accounts conform to company-wide policies.N/A
Pricing
AWS ConfigAWS Control Tower
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
AWS ConfigAWS Control Tower
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsWith AWS Config, you are charged based on the number of configuration items recorded, the number of active AWS Config rule evaluations and the number of conformance pack evaluations in your account. A configuration item is a record of the configuration state of a resource in your AWS account. An AWS Config rule evaluation is a compliance state evaluation of a resource by an AWS Config rule in your AWS account, and a conformance pack evaluation is the evaluation of a resource by an AWS Config rule within the conformance pack.
More Pricing Information
Community Pulse
AWS ConfigAWS Control Tower
Best Alternatives
AWS ConfigAWS Control Tower
Small Businesses
HashiCorp Terraform
HashiCorp Terraform
Score 8.8 out of 10
Armor
Armor
Score 6.0 out of 10
Medium-sized Companies
Ansible
Ansible
Score 9.2 out of 10
Druva Security Cloud
Druva Security Cloud
Score 9.5 out of 10
Enterprises
Ansible
Ansible
Score 9.2 out of 10
Druva Security Cloud
Druva Security Cloud
Score 9.5 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
AWS ConfigAWS Control Tower
Likelihood to Recommend
8.8
(6 ratings)
9.0
(4 ratings)
Usability
-
(0 ratings)
8.0
(1 ratings)
Performance
9.6
(2 ratings)
-
(0 ratings)
Ease of integration
6.2
(2 ratings)
-
(0 ratings)
User Testimonials
AWS ConfigAWS Control Tower
Likelihood to Recommend
Amazon AWS
It's really good if your infrastructure services is all in AWS, that means everything could be audited and monitored using AWS config. You also can create alarms to notify you or your team about any changes on your AWS resources which is very useful to prevent abuse if you have a fairly large team. It's also very useful whenever some third party wants to audit your AWS resources, if you have a fairly comprehensive AWS config configured, the auditing process will be easy since they only need to look at your AWS config setup.
Read full review
Amazon AWS
We were wanting to prove the concept of a low touch process for quickly spinning up boilerplate AWS environments. We were able to get started quickly and to ensure that the AWS Well-Architected Framework principles were followed - at least upfront - however, we found that for our use case and expertise level it ultimately wasn't a fit. We have the skills on our team to manage more of this on our own. My recommendation would be contingent on what skills are already available on your team: if you can "do it yourself" you might as well so that you don't pay for resources you don't need and you have finer grain control over what's created.
Read full review
Pros
Amazon AWS
  • The ability to track changes in AWS is paramount, AWS config allows you to do this
  • Allows the auditing of an AWS account
  • Can view history of an account that has AWS config enabled
Read full review
Amazon AWS
  • Easily create new AWS accounts.
  • Easily secure and manage AWS accounts.
  • Landing zone with SSO is a huge win for larger teams.
Read full review
Cons
Amazon AWS
  • It's only AWS, no third party.
  • Not the most intuitive interface, but with a little getting used to it is OK.
Read full review
Amazon AWS
  • The AWS SSO GUI is not very intuitive and determining how to apply policies to users without creating redundant logins has been a challenge.
  • The default guardrails do not fully encompass all the security checks that we needed.
  • There does not appear to be any way to control roles at the IAM level from the control tower account through the GUI.
  • Some features on AWS accounts still require logging into the individual account with the root user and cannot be done from AWS Control Tower.
Read full review
Usability
Amazon AWS
No answers on this topic
Amazon AWS
There is no way to easily close an AWS account whether it was created manually or via the AWS Control Tower. It takes too many steps to close it vs to provision a new AWS account
Read full review
Performance
Amazon AWS
Would rate lower for other workloads but for AWS workloads its simple to set up, cost effective and customisable. Primary use case is compliance from a governance perspective.
Read full review
Amazon AWS
No answers on this topic
Alternatives Considered
Amazon AWS
I do not know or have used any other product in AWS cloud space that matches what AWS Config provides. We have some custom built monitoring and governance, however that is there because AWS Config does not provide it currently.
Read full review
Amazon AWS
Using AWS Systems Manager and other slightly lower level components has been helpful for us to manage parts of our AWS presence at a more granular level than AWS Control Tower was designed for. It's not at all an apples-to-apples comparison as they solve different use cases, but for us, the use case associated with AWS Systems Manager was a better fit for our specific needs and skillsets. We did not need everything that AWS Control Tower was doing for us.
Read full review
Return on Investment
Amazon AWS
  • Enforcing audit requirements
  • Easy to set up alerting when there are rule breaches
  • Auto remediation reduces the manual policing of such breaches
Read full review
Amazon AWS
  • Less time manually deploying accounts which was error prone.
  • Central logging allowed us to have 1 place to view logs.
Read full review
ScreenShots