AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementMedium
A global company uses AWS Organizations and has a multi-account strategy. They want to ensure that all IAM users across all member accounts are required to use Multi-Factor Authentication (MFA) when accessing the AWS Management Console. Furthermore, they want to prevent any member account from disabling this MFA requirement. Which AWS service or feature should the security team use to enforce this policy centrally?
- AService Control Policies (SCPs) in AWS Organizations
- BIAM password policy in each account
- CAWS Config rules across all accounts
- DAWS Control Tower guardrails
Show answer & explanationAnswer & explanation
Correct answer: A. Service Control Policies (SCPs) in AWS Organizations
Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. You can use an SCP to explicitly deny actions that would disable MFA or allow console access without MFA, enforcing the requirement across all member accounts.
Why the other options are wrong
- B. IAM password policies are set at the account level and do not enforce MFA for console access, nor can they prevent accounts from changing them.
- C. AWS Config rules are for auditing compliance and reporting, not for preventing actions or enforcing policies across an organization.
- D. AWS Control Tower guardrails can enforce some best practices, but SCPs provide the direct granular control to deny specific actions at an organizational level.
Service Control Policies (SCPs)
Policy type used in AWS Organizations to manage permissions and set maximum available permissions for all accounts in an organization.
- Apply to all IAM users and roles in affected accounts, including the root user.
- Are preventative controls; they define the maximum available permissions.
- Do not grant permissions; they filter permissions granted by IAM policies.
Memory trick: Think of SCPs as the 'corporate police' that set the rules for everyone in the AWS Organization.