AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A global company uses AWS Organizations to manage multiple AWS accounts. They want to ensure that no account within any Organizational Unit (OU) can inadvertently or maliciously disable AWS CloudTrail logging. This policy must apply to all existing and future accounts automatically. Which AWS Organizations feature should be used?
- AIAM Policy
- BResource-based Policy
- CPermissions Boundary
- DService Control Policy (SCP)
Show answer & explanationAnswer & explanation
Correct answer: D. Service Control Policy (SCP)
Service Control Policies (SCPs) are JSON policies that specify the maximum permissions for an organization, OU, or account. They can be used to restrict actions, such as disabling CloudTrail, across all accounts, ensuring that even administrators in member accounts cannot perform prohibited actions.
Why the other options are wrong
- A. IAM policies define permissions for IAM identities within a single account, but cannot restrict actions at the organizational or OU level for all accounts.
- B. Resource-based policies are attached to resources (like S3 buckets or SQS queues) to control who can access them, not to restrict actions across an entire organization.
- C. A permissions boundary sets the maximum permissions that an IAM entity (user or role) can have. It operates within a single account and doesn't enforce restrictions across an entire organization.
AWS Organizations SCPs
Service Control Policies (SCPs) are an AWS Organizations feature that allows central governance by defining maximum available permissions for all accounts in an OU or organization.
- Act as 'guardrails' at the organizational level.
- Can explicitly deny actions, overriding IAM policies.
- Apply to all IAM principals in affected accounts, including the root user.
Memory trick: SCPs Secure Accounts, Stopping CloudTrail Snooze.