{"id":81851,"date":"2026-09-17T00:54:39","date_gmt":"2026-09-16T19:24:39","guid":{"rendered":"https:\/\/www.tothenew.com\/blog\/?p=81851"},"modified":"2026-09-29T14:51:07","modified_gmt":"2026-09-29T09:21:07","slug":"centralised-aws-backup-across-an-aws-organisation-using-terraform","status":"publish","type":"post","link":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/","title":{"rendered":"Centralised AWS Backup Across an AWS Organisation Using Terraform"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and Non-Production OUs, ensuring all tagged resources are protected without any per-account configuration.<\/p>\n<h2>Prerequisites<\/h2>\n<ul>\n<li>\n<h4>AWS Organization Requirements<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 85.7021%; height: 154px;\">\n<tbody>\n<tr style=\"height: 34px;\">\n<th style=\"width: 48.9787%; height: 34px; background-color: #b5c3e6;\" scope=\"row\">Requirement<\/th>\n<th style=\"width: 51.0213%; height: 34px; background-color: #b5c3e6;\" scope=\"row\">Detail<\/th>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 48.9787%; height: 24px;\">AWS Organizations<\/td>\n<td style=\"width: 51.0213%; height: 24px;\">Active with all features enabled<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 48.9787%; height: 24px;\">Prod OU<\/td>\n<td style=\"width: 51.0213%; height: 24px;\">Organizational Unit containing all production accounts<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 48.9787%; height: 24px;\">Non-Prod OU<\/td>\n<td style=\"width: 51.0213%; height: 24px;\">Organizational Unit containing dev \/ staging \/ UAT accounts<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 48.9787%; height: 24px;\">DevOps Tool Account<\/td>\n<td style=\"width: 51.0213%; height: 24px;\">A dedicated AWS account that acts as the management hub for infrastructure tools<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 48.9787%; height: 24px;\">Management Account<\/td>\n<td style=\"width: 51.0213%; height: 24px;\">Used only for delegation<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>AWS CLI Profiles<\/h4>\n<ul>\n<li>Two CLI profiles are required:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 50%; border-style: solid; background-color: #b5c3e6;\">Profile<\/th>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Account<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">default (or management)<\/td>\n<td style=\"width: 50%;\">Management Account (XXXXXXXXXX)<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">devops-tooling<\/td>\n<td style=\"width: 50%;\">DevOps Tooling Account (XXXXXXXXXXX)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table style=\"height: 24px; width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 100%; height: 24px;\"><span style=\"color: #ffffff;\"># Configure DevOps Tooling profile<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws configure &#8211;profile devops-tooling<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Enter: Access Key, Secret Key, region: eu-west-1<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify both profiles<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws sts get-caller-identity\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 # should show management account<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws sts get-caller-identity &#8211;profile devops-tooling\u00a0 # should show devops-tooling account<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2>Architecture<\/h2>\n<p>The implementation is split across two Terraform folders. The management folder runs once to configure delegation and create org-level backup policies. The devops-tooling folder deploys the CloudFormation StackSet that provisions resources in every member account.<\/p>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">Management Account<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u2514\u2500\u2500 Delegates DevOps Tooling as admin for Backup + CloudFormation<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u2514\u2500\u2500 Creates Org Backup Policies (prod + non-prod)<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u2514\u2500\u2500 Attaches policies to respective OUs<\/span><\/p>\n<p><span style=\"color: #ffffff;\">DevOps Tooling Account<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u2514\u2500\u2500 CloudFormation StackSet (DELEGATED_ADMIN)<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2514\u2500\u2500 Prod OU accounts \u00a0 \u2192 IAM Role + Backup Vault<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2514\u2500\u2500 Non-Prod OU accounts \u2192 IAM Role + Backup Vault<\/span><\/p>\n<p><span style=\"color: #ffffff;\">Member Accounts (auto-provisioned, zero manual steps)<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0Prod Account<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 IAM Role: aws-backup-org-role \u00a0 \u00a0 \u00a0 \u2190 StackSet<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 Backup Vault: org-backup-vault \u00a0 \u00a0 \u00a0 \u2190 StackSet<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u2514\u2500\u2500 Backup Plan: prod-backup-plan\u00a0 \u00a0 \u00a0 \u00a0 \u2190 Org Policy (3 rules)<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0Non-Prod Account<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 IAM Role: aws-backup-org-role \u00a0 \u00a0 \u00a0 \u2190 StackSet<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 Backup Vault: org-backup-vault \u00a0 \u00a0 \u00a0 \u2190 StackSet<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u2514\u2500\u2500 Backup Plan: non-prod-backup-plan \u00a0 \u2190 Org Policy (1 rule)<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Repository Structure<\/h2>\n<p>The Terraform code is split into two folders. The management\/ folder is run once. The devops-tooling\/ folder is used for all ongoing operations.<\/p>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">backup\/<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u251c\u2500\u2500 management\/\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u2190 Run ONCE from management account credentials<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502 \u00a0 \u251c\u2500\u2500 providers.tf \u00a0 \u00a0 \u00a0 \u00a0 \u2190 S3 backend, management account credentials<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502 \u00a0 \u251c\u2500\u2500 main.tf\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u2190 Delegation + Org Policies + Policy Attachments<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502 \u00a0 \u251c\u2500\u2500 locals.tf\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u2190 Builds backup policy JSON from ou_configs<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502 \u00a0 \u251c\u2500\u2500 variables.tf<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502 \u00a0 \u251c\u2500\u2500 outputs.tf<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502 \u00a0 \u2514\u2500\u2500 terraform.tfvars \u00a0 \u00a0 \u2190 ALL CONFIG: OU IDs, backup rules, retention<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2502<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u2514\u2500\u2500 devops-tooling\/\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u2190 All ongoing Terraform runs from here<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 providers.tf \u00a0 \u00a0 \u00a0 \u00a0 \u2190 S3 backend, devops-tooling profile<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 main.tf\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u2190 CloudFormation StackSet + Instances<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 locals.tf\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u2190 cfn_template (IAM role + vault template)<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 variables.tf<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u251c\u2500\u2500 outputs.tf<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0\u00a0\u00a0\u2514\u2500\u2500 terraform.tfvars \u00a0 \u00a0 \u2190 OU IDs (must match management\/terraform.tfvars)<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>AWS BACKUP_POLICY type in Organizations can only be created by the management account. The devops-tooling delegated admin permission covers backup operations only &#8211; not Organizations policy management. This is why policies are in management\/ and the StackSet is in devops-tooling\/<\/p>\n<h2>Management Account: One-Time Setup<\/h2>\n<p>All commands in this section run once from the management account CLI. After completion, these steps are never repeated.<\/p>\n<ul>\n<li>\n<h4>Enable Trusted Access<\/h4>\n<ul>\n<li>Run from a terminal authenticated to the management account:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\"># Verify CLI is on management account<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws sts get-caller-identity<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Expected: Account = management account ID<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Enable AWS Backup trusted access with Organizations<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations enable-aws-service-access \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;service-principal backup.amazonaws.com<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Enable CloudFormation StackSets trusted access<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations enable-aws-service-access \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;service-principal member.org.stacksets.cloudformation.amazonaws.com<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify both are enabled<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations list-aws-service-access-for-organization<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Enable CloudFormation Organizations Access<\/h4>\n<ul>\n<li>This is a separate activation step required for SERVICE_MANAGED StackSets to work from a delegated admin account:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">aws cloudformation activate-organizations-access<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws cloudformation describe-organizations-access<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Expected: Status: ENABLED<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Enable BACKUP_POLICY Type<\/h4>\n<ul>\n<li>Get the root ID and enable the BACKUP_POLICY policy type in the organization:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\"># Get the root ID<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations list-roots<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Note the Id value e.g. r-32ce<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Enable BACKUP_POLICY type<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations enable-policy-type \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;root-id YOUR_ROOT_ID \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;policy-type BACKUP_POLICY<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify \u2014 BACKUP_POLICY should now show Status: ENABLED<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations list-roots<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Without this step, creating BACKUP_POLICY type resources via Terraform will fail with AccessDeniedException even from the management account.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Management Folder Deployment<\/h2>\n<ul>\n<li>\n<h4>Update providers.tf<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Placeholder<\/th>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Replace with<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">TERRAFORM_STATE_BUCKET<\/td>\n<td style=\"width: 50%;\">S3 bucket name in management account<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Update terraform.tfvars<\/h4>\n<ul>\n<li>Set the DevOps Tooling account ID, region, and OU configurations:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li>\n<h4>\u00a0Deploy<\/h4>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">cd management<\/span><\/p>\n<p><span style=\"color: #ffffff;\">terraform init<\/span><\/p>\n<p><span style=\"color: #ffffff;\">terraform plan<\/span><\/p>\n<p><span style=\"color: #ffffff;\">terraform apply<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Expected output \u2014 5 resources created:<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Resource<\/th>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Count<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">aws_organizations_delegated_administrator<\/td>\n<td style=\"width: 50%;\">2 \u2014 backup.amazonaws.com + cloudformation<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">aws_backup_global_settings<\/td>\n<td style=\"width: 50%;\">1 \u2014 cross-account backup enabled<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">aws_organizations_policy<\/td>\n<td style=\"width: 50%;\">2 \u2014 prod-backup-policy + non-prod-backup-policy<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">aws_organizations_policy_attachment<\/td>\n<td style=\"width: 50%;\">2 \u2014 attached to Prod OU + Non-Prod OU<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>DevOps Tooling Folder Deployment<\/h2>\n<ul>\n<li>\n<h4>Update providers.tf<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Placeholder<\/th>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Replace with<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">TERRAFORM_STATE_BUCKET<\/td>\n<td style=\"width: 50%;\">S3 bucket name in DevOps Tooling account<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Update terraform.tfvars<\/h4>\n<ul>\n<li>The ou_configs map must contain the same OU IDs as management\/terraform.tfvars. The backup_rules and selection_tags are not used by the StackSet but must be present as the variable type requires them.<\/li>\n<\/ul>\n<\/li>\n<li>\n<h4>Key Configuration in main.tf<\/h4>\n<ul>\n<li>Two settings are required for the StackSet to work from a delegated admin account:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Setting<\/th>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Value<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">call_as<\/td>\n<td style=\"width: 50%;\">DELEGATED_ADMIN<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">capabilities<\/td>\n<td style=\"width: 50%;\">[&#8220;CAPABILITY_NAMED_IAM&#8221;]<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Deploy<\/h4>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">cd devops-tooling<\/span><\/p>\n<p><span style=\"color: #ffffff;\">terraform init<\/span><\/p>\n<p><span style=\"color: #ffffff;\">terraform plan<\/span><\/p>\n<p><span style=\"color: #ffffff;\">terraform apply<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># StackSet instance creation takes 1-2 minutes per OU \u2014 this is normal<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Expected output \u2014 3 resources created:<\/p>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Resource<\/th>\n<th style=\"width: 50%; background-color: #b5c3e6;\">Count<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">aws_cloudformation_stack_set<\/td>\n<td style=\"width: 50%;\">1 \u2014 aws-backup-org-setup<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\">aws_cloudformation_stack_set_instance<\/td>\n<td style=\"width: 50%;\">2 \u2014 one per OU (prod + non-prod)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Tagging Resources for Backup<\/h2>\n<p>AWS Backup selects resources based on tags. A resource must carry ALL tags listed in selection_tags for its OU to be included in backup.<\/p>\n<ul>\n<li>\n<h4>Production resources<\/h4>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">tags = {<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0Backup\u00a0 \u00a0 \u00a0 = &#8220;true&#8221;<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0Environment = &#8220;prod&#8221;<\/span><\/p>\n<p><span style=\"color: #ffffff;\">}<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Non-Production resources<\/h4>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">tags = {<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0Backup\u00a0 \u00a0 \u00a0 = &#8220;true&#8221;<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0Environment = &#8220;non-prod&#8221;<\/span><\/p>\n<p><span style=\"color: #ffffff;\">}<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>\u00a0Supported Resource Types<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%; height: 120px;\">\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 50%; height: 24px;\">Category<\/td>\n<td style=\"width: 50%; height: 24px;\">Services<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 50%; height: 24px;\">Compute<\/td>\n<td style=\"width: 50%; height: 24px;\">EC2 instances, EBS volumes<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 50%; height: 24px;\">Database<\/td>\n<td style=\"width: 50%; height: 24px;\">RDS, Aurora, DynamoDB, DocumentDB, Neptune<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 50%; height: 24px;\">Storage<\/td>\n<td style=\"width: 50%; height: 24px;\">EFS, FSx, S3<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 50%; height: 24px;\">Hybrid<\/td>\n<td style=\"width: 50%; height: 24px;\">AWS Storage Gateway (Volume Gateway)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Backup Plans<\/h2>\n<ul>\n<li>\n<h4>Production<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 33.3333%; background-color: #b5c3e6;\">Rule<\/th>\n<th style=\"width: 33.3333%; background-color: #b5c3e6;\">Schedule<\/th>\n<th style=\"width: 33.3333%; background-color: #b5c3e6;\">Retention<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Daily<\/td>\n<td style=\"width: 33.3333%;\">Every day at 02:00 UTC<\/td>\n<td style=\"width: 33.3333%;\">30 days<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Weekly<\/td>\n<td style=\"width: 33.3333%;\">Every Sunday at 03:00 UTC<\/td>\n<td style=\"width: 33.3333%;\">60 days<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Monthly<\/td>\n<td style=\"width: 33.3333%;\">1st of every month at 04:00 UTC<\/td>\n<td style=\"width: 33.3333%;\">365 days<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Non-Production<\/h4>\n<\/li>\n<\/ul>\n<table style=\"border-collapse: collapse; width: 100%;\">\n<tbody>\n<tr>\n<th style=\"width: 33.3333%; background-color: #b5c3e6;\">Rule<\/th>\n<th style=\"width: 33.3333%; background-color: #b5c3e6;\">Schedule<\/th>\n<th style=\"width: 33.3333%; background-color: #b5c3e6;\">Retention<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Daily<\/td>\n<td style=\"width: 33.3333%;\">Every day at 02:00 UTC<\/td>\n<td style=\"width: 33.3333%;\">7 days<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Backup Storage<\/h4>\n<\/li>\n<\/ul>\n<p>All recovery points are stored in the originating account&#8217;s own vault. No data crosses account boundaries.<\/p>\n<table style=\"width: 100%; border-collapse: collapse; border-style: solid; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">Prod Account \u00a0 \u00a0 \u2192 resources backed up \u2192 org-backup-vault (prod account)<\/span><\/p>\n<p><span style=\"color: #ffffff;\">Non-Prod Account \u2192 resources backed up \u2192 org-backup-vault (non-prod account)<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u00a0Making Changes<\/h2>\n<p>All configuration changes are made in terraform.tfvars files only. After editing, run terraform plan followed by terraform apply in the relevant folder.<\/p>\n<ul>\n<li>\n<h4>\u00a0Add a New Backup Rule<\/h4>\n<ul>\n<li>Update management\/terraform.tfvars only. Add a new entry to backup_rules of the relevant OU:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li>\n<h4>Add a New Tag to Resource Selection<\/h4>\n<ul>\n<li>Update selection_tags in management\/terraform.tfvars for the relevant OU:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li>\n<h4>Add a New OU<\/h4>\n<ul>\n<li>Update terraform.tfvars in BOTH folders:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>New Account Auto-Provisioning<\/h2>\n<p>When a new AWS account is added to a managed OU, the following happens automatically with no manual steps required:<\/p>\n<ul>\n<li>Account joins the Prod or Non-Prod OU<\/li>\n<li>CloudFormation StackSet detects the new account (auto_deployment = true)<\/li>\n<li>IAM role aws-backup-org-role &amp; Backup vault org-backup-vault is created in the new account<\/li>\n<li>Org backup policy already attached to the OU applies automatically<\/li>\n<li>Any resource tagged Backup=true is backed up on the next scheduled run<\/li>\n<\/ul>\n<h2>\u00a0Verification<\/h2>\n<ul>\n<li>\n<h4>Verify Org Backup Policies<\/h4>\n<ul>\n<li>Run from management account CLI:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\"># List all backup policies in the org<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations list-policies &#8211;filter BACKUP_POLICY<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Expected: prod-backup-policy + non-prod-backup-policy<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify prod policy is attached to Prod OU<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations list-policies-for-target \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;target-id YOUR_PROD_OU_ID \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;filter BACKUP_POLICY<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify non-prod policy is attached to Non-Prod OU<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws organizations list-policies-for-target \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;target-id YOUR_NON_PROD_OU_ID \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;filter BACKUP_POLICY<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Verify StackSet Instances<\/h4>\n<ul>\n<li>Note: must include &#8211;call-as DELEGATED_ADMIN when querying as the devops-tooling account:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">aws cloudformation list-stack-instances \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;stack-set-name aws-backup-org-setup \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;call-as DELEGATED_ADMIN \\<\/span><\/p>\n<p><span style=\"color: #ffffff;\">\u00a0\u00a0&#8211;profile devops-tooling<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Expected: both member accounts with Status: CURRENT, DetailedStatus: SUCCEEDED<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>\u00a0Verify Member Account Resources<\/h4>\n<ul>\n<li>Configure a CLI profile for the prod account, then run:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<table style=\"width: 100%; border-collapse: collapse; background-color: #000000;\" border=\"2\">\n<tbody>\n<tr>\n<td style=\"width: 100%;\"><span style=\"color: #ffffff;\">aws iam get-role &#8211;role-name aws-backup-org-role &#8211;profile prod<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws backup list-backup-vaults &#8211;region eu-west-1 &#8211;profile prod<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Expected: org-backup-vault<\/span><\/p>\n<p><span style=\"color: #ffffff;\"># Verify backup plan exists<\/span><\/p>\n<p><span style=\"color: #ffffff;\">aws backup list-backup-plans &#8211;region eu-west-1 &#8211;profile prod<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>\n<h4>Run an On-Demand Backup (Optional)<\/h4>\n<ul>\n<li>Tag a resource in the prod account with Backup=true and Environment=prod, then trigger a manual job:<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>\u00a0Conclusion<\/h2>\n<p>AWS Backup is fully operational across all member accounts in the organisation. The CloudFormation StackSet has deployed the IAM role and backup vault into each account. Org-level backup policies are attached to the relevant OUs and are enforcing the configured schedules and retention periods automatically.<\/p>\n<p>All recovery points are stored within the originating account &#8211; no data moves across account boundaries. Any new account added to a managed OU is provisioned automatically without any manual intervention.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and [&hellip;]<\/p>\n","protected":false},"author":1906,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":1,"footnotes":""},"categories":[2348],"tags":[473,1916,1892,7041,1585],"class_list":["post-81851","post","type-post","status-publish","format-standard","hentry","category-devops-technology","tag-backup","tag-cloud","tag-devops","tag-security","tag-terraform"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Devendra Kumar Singh\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"TO THE NEW BLOG\" \/>\n\t\t<meta property=\"og:type\" content=\"blog\" \/>\n\t\t<meta property=\"og:title\" content=\"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@tothenew\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#article\",\"name\":\"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog\",\"headline\":\"Centralised AWS Backup Across an AWS Organisation Using Terraform\",\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/devendra-singh\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"},\"datePublished\":\"2026-09-17T00:54:39+05:30\",\"dateModified\":\"2026-09-29T14:51:07+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#webpage\"},\"articleSection\":\"DevOps, backup, cloud, devops, Security, terraform\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/#listItem\",\"name\":\"DevOps\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/#listItem\",\"position\":2,\"name\":\"DevOps\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#listItem\",\"name\":\"Centralised AWS Backup Across an AWS Organisation Using Terraform\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#listItem\",\"position\":3,\"name\":\"Centralised AWS Backup Across an AWS Organisation Using Terraform\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/devops-technology\\\/#listItem\",\"name\":\"DevOps\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\",\"name\":\"TO THE NEW Blog\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/devendra-singh\\\/#author\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/devendra-singh\\\/\",\"name\":\"Devendra Kumar Singh\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#authorImage\",\"url\":\"https:\\\/\\\/newersworld-sf-static.tothenew.net\\\/prod\\\/profilePicFolder\\\/2faf8525-6db6-475c-bde4-8e1251d636fd_Devendra-Kumar-Singh-Profile-Pitcure.jpeg\",\"width\":96,\"height\":96,\"caption\":\"Devendra Kumar Singh\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#webpage\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/\",\"name\":\"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog\",\"description\":\"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/centralised-aws-backup-across-an-aws-organisation-using-terraform\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/devendra-singh\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/devendra-singh\\\/#author\"},\"datePublished\":\"2026-09-17T00:54:39+05:30\",\"dateModified\":\"2026-09-29T14:51:07+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\",\"name\":\"TO THE NEW Blog\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog","description":"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and","canonical_url":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#article","name":"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog","headline":"Centralised AWS Backup Across an AWS Organisation Using Terraform","author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/devendra-singh\/#author"},"publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"},"datePublished":"2026-09-17T00:54:39+05:30","dateModified":"2026-09-29T14:51:07+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#webpage"},"isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#webpage"},"articleSection":"DevOps, backup, cloud, devops, Security, terraform"},{"@type":"BreadcrumbList","@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.tothenew.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/#listItem","name":"DevOps"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/#listItem","position":2,"name":"DevOps","item":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#listItem","name":"Centralised AWS Backup Across an AWS Organisation Using Terraform"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#listItem","position":3,"name":"Centralised AWS Backup Across an AWS Organisation Using Terraform","previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/#listItem","name":"DevOps"}}]},{"@type":"Organization","@id":"https:\/\/www.tothenew.com\/blog\/#organization","name":"TO THE NEW Blog","url":"https:\/\/www.tothenew.com\/blog\/"},{"@type":"Person","@id":"https:\/\/www.tothenew.com\/blog\/author\/devendra-singh\/#author","url":"https:\/\/www.tothenew.com\/blog\/author\/devendra-singh\/","name":"Devendra Kumar Singh","image":{"@type":"ImageObject","@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#authorImage","url":"https:\/\/newersworld-sf-static.tothenew.net\/prod\/profilePicFolder\/2faf8525-6db6-475c-bde4-8e1251d636fd_Devendra-Kumar-Singh-Profile-Pitcure.jpeg","width":96,"height":96,"caption":"Devendra Kumar Singh"}},{"@type":"WebPage","@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#webpage","url":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/","name":"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog","description":"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/#breadcrumblist"},"author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/devendra-singh\/#author"},"creator":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/devendra-singh\/#author"},"datePublished":"2026-09-17T00:54:39+05:30","dateModified":"2026-09-29T14:51:07+05:30"},{"@type":"WebSite","@id":"https:\/\/www.tothenew.com\/blog\/#website","url":"https:\/\/www.tothenew.com\/blog\/","name":"TO THE NEW Blog","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"TO THE NEW BLOG","og:type":"blog","og:title":"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog","og:description":"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and","og:url":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/","og:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","og:image:secure_url":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","twitter:card":"summary","twitter:site":"@tothenew","twitter:title":"Centralised AWS Backup Across an AWS Organisation Using Terraform | TO THE NEW Blog","twitter:description":"Introduction This blog provides step-by-step instructions to implement centralised AWS Backup across an AWS Organisation using Terraform. Backup policies are managed from a dedicated DevOps Tooling account using Delegated Administration. A CloudFormation StackSet automatically deploys the required IAM role and backup vault to all member accounts. Org-level backup policies are attached to the Production and","twitter:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png"},"aioseo_meta_data":{"post_id":"81851","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"created":"2026-08-27 18:07:39","updated":"2026-09-29 09:21:09","focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"breadcrumb_settings":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/\" title=\"DevOps\">DevOps<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tCentralised AWS Backup Across an AWS Organisation Using Terraform\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.tothenew.com\/blog"},{"label":"DevOps","link":"https:\/\/www.tothenew.com\/blog\/category\/devops-technology\/"},{"label":"Centralised AWS Backup Across an AWS Organisation Using Terraform","link":"https:\/\/www.tothenew.com\/blog\/centralised-aws-backup-across-an-aws-organisation-using-terraform\/"}],"_links":{"self":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/81851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/users\/1906"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/comments?post=81851"}],"version-history":[{"count":5,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/81851\/revisions"}],"predecessor-version":[{"id":83769,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/81851\/revisions\/83769"}],"wp:attachment":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/media?parent=81851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/categories?post=81851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/tags?post=81851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}