Updated on 2024-05-24 GMT+08:00

Overview of Organization Management

What Is Organizations?

Huawei Cloud Organizations is an account management service for consolidating multiple Huawei Cloud accounts into a single organization so you can manage them all in one place. An organization is composed of one management account, multiple member accounts, one root organizational unit (OU), and other OUs. The root OU and other OUs are organized in a hierarchical, tree-like structure. You can group your accounts into the root OU or any of the other OUs. For information about Organizations, see What Is Organizations?

After you set up a landing zone using a management account, the managed organizational structure, OUs, and accounts are displayed on the organization management page.

Basic Concepts

  • Organization

    An entity that you create to manage multiple accounts. Each organization is composed of a management account, member accounts, a root OU, and various other OUs. An organization has exactly one management account along with several member accounts. You can organize the accounts in a hierarchical, tree-like structure with the root OU at the top and nested OUs under it. Each member account can be directly under the root OU or placed under one of the other OUs. The organization management page displays the organization structure.

  • Root OU

    The root OU is located at the top of the organizational tree, and the branches representing other OUs and accounts reach down. The root OU is displayed on the top of the organization.

  • Core OU

    When you are setting up a landing zone, a preset core OU (default name: Security) is automatically displayed in the organizational structure. This OU contains two core accounts: a log archive account and a security audit account (or an audit account for short).

  • OUs

    A container or grouping unit for member accounts. It can be understood as a department, a subsidiary, a project family, or the like, of your enterprise. An OU can also contain other OUs. Each OU can have exactly one parent OU, but a parent OU can have multiple child OUs or nested member accounts.

  • Management account

    The account used to set up a landing zone. You can use the management account to register OUs and enroll accounts and also manage both in the landing zone.

  • Member accounts

    An account directly in the root OU or placed in one of the other OUs.

  • Registered OUs

    If you create OUs in RGC, they will be registered automatically. If you create OUs in Organizations, you need to register them manually so they can be governed in the landing zone.

  • Enrolled accounts

    If you create accounts in RGC, they will be automatically enrolled. If you create accounts in Organizations, you need to manually enroll them so that they can be governed in the landing zone.