A large enterprise uses AWS Organizations to manage multiple AWS accounts. They need to enforce a mandatory security policy that prevents any IAM user or role in any account from disabling AWS CloudTrail, even for administrative users, to ensure continuous auditing and compliance. This policy must be applied centrally and universally across all accounts, including newly created ones, and must be immutable by individual account administrators. Which AWS Organizations feature should the Solutions Architect leverage?
- AIAM Policies attached to individual IAM users and roles in each account.
- BAWS Config rules deployed in each account to detect and remediate CloudTrail configuration changes.
- CService Control Policies (SCPs) applied to Organizational Units (OUs) or the root of the organization.
- DResource-based policies attached to the CloudTrail S3 bucket and SNS topic.
Show answer & explanationAnswer & explanation
Correct answer: C. Service Control Policies (SCPs) applied to Organizational Units (OUs) or the root of the organization.
Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. They act as guardrails, setting the maximum available permissions for IAM users and roles in affected accounts, ensuring that even administrators cannot perform actions explicitly denied by an SCP, such as disabling CloudTrail.
Why the other options are wrong
- A. IAM policies are account-specific and can be overridden or modified by administrators within those accounts, failing the requirement for an immutable, centrally enforced policy.
- B. AWS Config rules detect non-compliant resources but do not prevent actions from occurring. While useful for auditing, they do not enforce a preventative control against disabling CloudTrail, and deploying them in each account is not a centralized management solution for prevention.
- D. Resource-based policies protect specific resources but do not prevent an IAM principal from disabling the CloudTrail service itself or creating a new trail without the policy, nor do they apply universally to all accounts.
Service Control Policies (SCPs)
A type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.
- Applied to the organization root, OUs, or individual accounts.
- Act as 'guardrails' for permissions, not granting permissions directly.
- Prevent even root users or administrators in member accounts from performing denied actions.
Memory trick: SCPs are like the organizational constitution, setting the absolute limits for everyone.