A security engineer is configuring AWS Organizations for a new enterprise. The organization has several Organizational Units (OUs) for different departments, and each OU contains multiple AWS accounts. The engineer needs to ensure that no IAM user or role in any account can disable AWS CloudTrail logging. This restriction must apply even to administrators within the member accounts but should not affect the root user of the management account. Which AWS Organizations feature should be used?
- APreventive Guardrails using AWS Config rules.
- BA CloudTrail trail configured with 'organization trail' enabled.
- CIAM policies attached to specific users and roles in each member account.
- DService Control Policies (SCPs) applied to the root of the organization.
Show answer & explanationAnswer & explanation
Correct answer: D. Service Control Policies (SCPs) applied to the root of the organization.
Service Control Policies (SCPs) are powerful guardrails in AWS Organizations that specify the maximum permissions that any IAM user or role can have within the affected accounts. By attaching an SCP to the root of the organization that explicitly denies `cloudtrail:StopLogging` and `cloudtrail:DeleteTrail` actions, this restriction is enforced across all member accounts, even for administrators, while allowing the management account's root user to bypass it.
Why the other options are wrong
- A. AWS Config rules are detective controls that assess compliance after a change has occurred. They can notify or remediate but cannot prevent an action like disabling CloudTrail logging from happening in the first place. SCPs are preventive.
- B. Configuring an organization trail ensures CloudTrail logs events from all accounts, but it does not prevent users or roles in member accounts from stopping logging or deleting trails if their IAM policies allow it. SCPs provide the preventive control.
- C. IAM policies are identity-based and would need to be applied to every user and role in every account, which is not scalable or centrally enforceable for a strong organizational guardrail. An administrator could simply modify or remove their own IAM policy.
AWS Service Control Policies (SCPs)
Policies in AWS Organizations that define the maximum available permissions for all IAM users and roles in affected member accounts.
- Preventive guardrails, not access grants.
- Apply to all IAM users and roles in member accounts.
- Do not affect the root user of the management account.
- Can be attached to the root, OUs, or individual accounts.
Memory trick: SCPs are the organizational rules, preventing all the fools.