AWS SSO - what OU/account to use?



We have a greenfield environment and I am looking at the best way to set up AWS Organization and underlying OUs with accounts. We also use SSO. According to , we should only have any services in management account. I am trying to figure out OU/account should SSO go to according to that document. Should it go to Shared Infra? Or are there any limitations that I should know of and SSO must be part of Management account?

Easiest way to setup the landing zone is to use Control Tower. The only caveat with SSO is that you need to deploy CT in the management account in the same region where the existing SSO is deployed. Control Tower wont change the existing SSO. SSO will live in the management account and is not considered a "workload".


