A global enterprise uses multiple AWS accounts managed under AWS Organizations. The security team needs to enforce a policy that prevents any IAM user or role in any account from creating EC2 instances outside of approved AWS Regions (e.g., only `us-east-1` and `eu-west-1`). This policy must apply to all existing and newly created accounts within the organization. Which AWS service should the SysOps administrator use to implement this control?
- AAWS Organizations Service Control Policies (SCPs) applied at the root of the organization.
- BAWS CloudFormation StackSets to deploy region-specific resource policies.
- CIAM policies applied to individual users and roles in each account.
- DAWS Config rules deployed to each account to detect non-compliant instances.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Organizations Service Control Policies (SCPs) applied at the root of the organization.
AWS Organizations Service Control Policies (SCPs) are guardrails that you can use to set the maximum available permissions for all IAM users and roles in an AWS account or organizational unit (OU). By applying an SCP at the root of the organization, you can effectively restrict the ability to perform actions (like `ec2:RunInstances`) in unapproved AWS Regions for all accounts, both existing and future. This is the most effective and scalable way to enforce region restrictions across an entire organization.
Why the other options are wrong
- B. CloudFormation StackSets deploy resources, but they are not designed to enforce preventive organizational-wide policies that restrict actions across all accounts and users. They can't prevent a user from manually launching an instance in an unapproved region if the underlying IAM permissions allow it.
- C. Applying IAM policies to individual users and roles would be a manual, error-prone, and unscalable approach across multiple accounts and an entire organization, especially for new accounts.
- D. AWS Config rules detect non-compliance after it occurs and can trigger remediation, but they are not preventive controls that block actions from happening in the first place. The requirement is to 'prevent' creation.
AWS Organizations Service Control Policies (SCPs)
SCPs are policy types that allow you to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in your organization, acting as guardrails.
- Preventive security control.
- Applies to all IAM users/roles in affected accounts/OUs.
- Can restrict actions by AWS Region.
- Centralized management for multi-account organizations.
Memory trick: SCPs are the 'S'ecurity 'C'hecks 'P'reventing 'P'roblems across the entire 'O'rganization.