AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A large enterprise uses AWS Organizations to manage multiple AWS accounts. They want to enforce a baseline set of security controls across all member accounts, such as disallowing the creation of IAM users without MFA and preventing the use of unencrypted S3 buckets. This enforcement must apply to new accounts automatically and cannot be overridden by individual account administrators. Which AWS Organizations feature should be used?

  1. ATag Policies
  2. BAWS Config rules
  3. CService Control Policies (SCPs)
  4. DIAM policies applied to the Organization's root
Show answer & explanation

Correct answer: C. Service Control Policies (SCPs)

Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions across multiple accounts. They act as guardrails, defining the maximum available permissions for IAM users and roles in member accounts. SCPs cannot be overridden by individual account administrators, ensuring mandatory security controls like disallowing unencrypted S3 buckets or IAM users without MFA are enforced across the entire organization.

Why the other options are wrong

  • A. Tag Policies enforce tagging standards but do not control service permissions or resource configurations like encryption or MFA.
  • B. AWS Config rules assess compliance of resources against desired configurations and can report non-compliance, but they do not *prevent* non-compliant actions from occurring. They are reactive, not proactive enforcement mechanisms like SCPs.
  • D. IAM policies applied to the Organization's root would affect the root user of the management account, but they do not propagate or enforce restrictions on IAM users and roles *within* member accounts in the same way SCPs do. SCPs explicitly limit what IAM policies can grant.

AWS Organizations SCPs

Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to manage permissions in your organization. They define the maximum permissions for all IAM users and roles in member accounts.

  • Act as guardrails, defining maximum permissions.
  • Applied to OUs or individual accounts in an Organization.
  • Cannot be overridden by member account administrators.
  • Essential for enforcing mandatory, organization-wide security controls.

Memory trick: SCPs: Strong Centralized Protection

More Design Secure Architectures questions