A security team needs to enforce strict network configurations for all newly provisioned AWS accounts within their organization. Specifically, they want to prevent any new account from creating S3 buckets that are publicly accessible. This policy must apply to all accounts, even those created in the future, and cannot be overridden by individual account administrators. Which AWS Organizations feature should be used?
- AAWS Config Rules
- BAWS CloudFormation StackSets
- CService Control Policies (SCPs)
- DOrganizational Units (OUs)
Show answer & explanationAnswer & explanation
Correct answer: C. Service Control Policies (SCPs)
Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. They act as guardrails, setting maximum available permissions for IAM users and roles in affected accounts, and cannot be overridden by local account administrators. An SCP can explicitly deny the `s3:PutBucketPublicAccessBlock` action or other S3 public access related actions.
Why the other options are wrong
- A. AWS Config rules monitor compliance but don't prevent actions. They can't enforce a hard block that cannot be overridden.
- B. CloudFormation StackSets deploy resources across accounts but don't enforce preventive, unoverridable permissions at the organization level.
- D. Organizational Units (OUs) are used to group accounts, but SCPs are the mechanism applied to OUs (or individual accounts) to enforce policies.
Service Control Policies (SCPs)
Service Control Policies (SCPs) are a type of organization policy in AWS Organizations that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.
- Applied to OUs or individual accounts.
- Act as permission guardrails; policies cannot grant more permissions than the SCP allows.
- Cannot be overridden by IAM policies within member accounts.
Memory trick: SCPs are like the strict *School Principal* for your AWS accounts, setting the rules that no one can break.