Security & IAM
AWS Firewall Manager
AWS Firewall Manager centrally deploys and audits supported network and application security policies across AWS Organizations accounts and resources, including WAF, Shield Advanced, security groups, network ACLs, Network Firewall, and Route 53 Resolver DNS Firewall.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Firewall Manager.
AWS Firewall Manager pricing and cost programs
Pricing model: Policy and account usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Policy scope · Accounts and Regions · Protected resources · Underlying security services
Programs and modes: WAF policies · Shield Advanced policies · Security group policies · Network Firewall policies
Firewall Manager fees are additional to the security services and resources managed by each policy.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Firewall Manager?
- Applies a common security baseline across accounts and automatically evaluates new in-scope accounts and resources.
- Supports multiple protection types and policies with OU, account, resource-type, and tag-based scope.
- Can report noncompliance before enforcement or automatically remediate supported resources according to the selected policy.
How to implement AWS Firewall Manager
- Integrate AWS Organizations and AWS Config as required, choose a delegated security administrator, inventory Regions and resources, and define ownership, exceptions, cleanup, and break-glass procedures.
- Create one policy per protection intent, choose precise accounts, OUs, resources and tags, define managed and custom controls, and start with monitoring or automatic remediation disabled where the policy supports it.
- Review compliant and noncompliant resources, validate impact in pilot OUs, enable remediation progressively, monitor Config and Firewall Manager status, and test account, resource, tag, and OU lifecycle changes.
AWS Firewall Manager best practices
- Use a delegated administrator outside the Organizations management account, separate policies by purpose and risk, and keep scope definitions simple enough to audit.
- Pilot before automatic remediation, understand what happens when a resource leaves scope, and document exceptions rather than using ambiguous tags or broad exclusions.
- Create policies in every required Region, treat CloudFront as global where applicable, review new service capabilities and accounts, and alert on persistent noncompliance or failed remediation.
AWS Firewall Manager use cases and server impact
- Organization-wide WAF baselines
- Central Network Firewall and DNS Firewall policy
- Security-group, network ACL, and Shield governance
Replaces custom cross-account firewall rollout and compliance controllers, while policy design, exception governance, application testing, network routing, and incident response remain yours.
Official implementation resources
Commonly paired AWS services
- AWS Organizations — Multi-account mgmt
- AWS WAF — Web app firewall
- AWS Network Firewall — Managed network firewall
- AWS Shield — DDoS protection
- AWS Security Hub — Security posture
- AWS Config — Resource compliance
- AWS CloudTrail — API audit logging