AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium

A global media company uses AWS Organizations to manage multiple accounts. They want to ensure that all accounts within a specific Organizational Unit (OU) adhere to strict security policies, such as disallowing the creation of IAM users with administrative permissions and preventing the use of unapproved AWS regions. These policies must be enforced at the account level, regardless of the IAM permissions granted to individual users or roles within those accounts. Which AWS service or feature should a Solutions Architect recommend to implement these preventative controls?

  1. AIAM Roles with explicit Deny policies.
  2. BService Control Policies (SCPs).
  3. CIAM Permission Boundaries.
  4. DAWS Config rules with auto-remediation.
Show answer & explanation

Correct answer: B. Service Control Policies (SCPs).

Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, or for specific OUs. They are preventative controls that apply to all identities, including the root user, within affected accounts.

Why the other options are wrong

  • A. IAM Roles with explicit Deny policies are effective for specific roles, but they do not apply to the root user or other roles unless explicitly attached, and they require management within each account. SCPs provide a higher-level, organizational-wide control.
  • C. IAM Permission Boundaries set the maximum permissions that an identity-based policy can grant to an IAM entity (user or role). While powerful, they are still managed within individual accounts and don't provide the top-down, preventative control across OUs that SCPs offer.
  • D. AWS Config rules are detective controls that identify non-compliant resources and can trigger auto-remediation. They do not prevent actions from being taken in the first place, which is required for preventative controls.

Service Control Policies (SCPs)

Policies that define the maximum available permissions for all accounts in an AWS Organization or a specific Organizational Unit (OU). They are preventative guardrails.

  • Applied at the OU or account level in AWS Organizations.
  • Preventative controls, not detective.
  • Affects all IAM users and roles, including the root user.
  • Cannot grant permissions; can only restrict them.

Memory trick: SCPs are the 'Organization's Gatekeepers', setting the absolute limits for everyone.

More Continuously Improve Existing Solutions questions