Deny iam:CreateUser with an SCP attached to the research team's account

Answer Correct answer: C — attach an SCP denying iam:CreateUser to the research team's account so the deny cannot be overridden by AdministratorAccess.

A cloud team uses AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On) to manage a company's AWS accounts. The company recently established a research team. The research team requires the ability to fully manage the resources in its account. The research team must not be able to create IAM users. The cloud team creates a Research Administrator permission set in IAM Identity Center for the research team. The permission set has the AdministratorAccess AWS managed policy attached. The cloud team must ensure that no one on the research team can create IAM users. Which solution will meet these requirements?

  1. Create an IAM policy that denies the iam:CreateUser action. Attach the IAM policy to the Research Administrator permission set.
  2. Create an IAM policy that allows all actions except the iam:CreateUser action. Use the IAM policy to set the permissions boundary for the Research Administrator permission set.
  3. Create an SCP that denies the iam:CreateUser action. Attach the SCP to the research team's AWS account. Correct Answer
  4. Create an AWS Lambda function that deletes IAM users. Create an Amazon EventBridge rule that detects the IAM CreateUser event. Configure the rule to invoke the Lambda function.

Community Votes

C
56%
A
44%

56% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement is a guarantee that user creation is impossible for the team, not merely a reduction in what the permission set grants. An SCP is an explicit deny evaluated above identity-based policies, so it cannot be overridden by the AdministratorAccess managed policy, and it applies to all principals in the member account including root (C). Option A attaches a deny to the permission set, which does stop members using that permission set but leaves any other principal or credential path in the account able to create users; option B uses a permissions boundary, which caps maximum permissions rather than denying an action outright.

The Research Administrator permission set grants AdministratorAccess, and the requirement is that no one on the research team can create IAM users. A deny on iam:CreateUser cannot be overridden by any allow, so attaching an SCP with that deny to the research team's account creates an organizational guardrail that the AdministratorAccess policy cannot bypass, and it covers every principal operating in that account regardless of how they authenticate.

Attaching a deny policy to the permission set (A)—while this blocks members who assume the Research Administrator permission set, it does not cover other principals or access paths in the account, so it does not deliver the unconditional guarantee the requirement asks for. Using a permissions boundary that allows everything except iam:CreateUser (B)—a boundary caps the maximum permissions of a principal but is a delegation-limits feature evaluated alongside identity policies; the SCP deny is the harder organizational guardrail that AdministratorAccess cannot override.

Community Discussion (17 comments)

CloudHell 👍 8 Selected: C
It's C for me, here is a link with a similar scenario: https://asecure.cloud/a/scp_deny_iam_user_creation_w_exception/
dkp 👍 7 Selected: C
While IAM policies can deny actions, they are typically attached to individual users or roles. In this scenario, you want to restrict user creation across the entire research team's account, making an SCP the more appropriate choice.
teo2157 👍 2 Selected: A
A as the restriction just needs to be applied to the research team but not the whole account users
MrTizz 👍 3 Selected: A
The wording is that only the research team should not be allowed to create users. This is A as the Permission Set will apply to just them. If you choose C it's an account wide deny so no other user or admins would be able to create a user which is outside the scope of the question.
spring21 👍 3 Selected: A
IAM Policy to Deny iam:CreateUser An IAM policy is applied to individual IAM users, groups, or roles within an AWS account. Here's an example policy that denies the iam:CreateUser action: IAM Policy JSON json Copy code { "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": "iam:CreateUser", "Resource": "*" } ] } Steps to Attach IAM Policy to Research Administrator Permission Set: Navigate to AWS IAM Identity Center (SSO). Select the Permission Sets section. Choose the Research Administrator permission set. Attach the custom policy above to the permission set by selecting Add permissions → Custom policy.
Impromptu 👍 2 Selected: A
A meets the requirements. C would deny CreateUser for all the IAM entities in the account, not only the research team
GripZA 👍 2 Selected: A
For those who selected C, why would you create ab SCP that will deny any IAM user from creating another IAM when the question clearly states only the research team shouldn't be able to create an IAM user? the deny policy will restrict only the Research Administrator permission set, which is what we want.
jamesf 👍 3 Selected: C
i go for C just make sure no one can create account scp also can create with exception as mentioned by @CloudHell
tgv 👍 5 Selected: A
I'll go for A as the question says: "The cloud team must ensure that no one on the research team can create IAM users." C will block everybody (not just the research team)
xdkonorek2 👍 4 Selected: C
C, A is not enough due research team still could create iam role with that allows him to create iam user and e.g. invoke lambda that does it for him obviously unwanted implication is that no one in this account can create IAM users even admins, but still it fulfills the requirements
that1guy 👍 4 Selected: A
A, only the research team shouldn't be able to create IAM users.
seetpt 👍 3 Selected: C
C for me
c3518fc 👍 4 Selected: C
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_attach.html
tristan_07 👍 5 Selected: C
C is the answer. IAM policy is not as scalable or centralized as using an SCP. You can attach an SCP to the organization root, to an organizational unit (OU), or directly to an account https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_attach.html
WhyIronMan 👍 2 Selected: A
A is the correct option since you can not apply SCP directly to an AWS Account (need to be OU)
rkddkwlrkwhgdk 👍 4 Selected: A
SCP can be applied to an OU. Therefore, the answer is A.
ogerber 👍 1 Selected: A
Its A, when you attach the SCP no one will be able to create new user not just the team

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A service control policy that explicitly denies iam:CreateUser creates an organizational guardrail whose deny takes precedence over any identity-based allow, including the AdministratorAccess managed policy attached to the permission set, because effective permissions are the intersection of what identity-based policies allow and what the SCP permits. AWS documentation also confirms that SCPs affect all users and roles in the attached member account, including the root user, so attaching the SCP to the research team's account makes the prohibition unconditional for everyone operating there. This is the AWS-suggested answer for this item.

Why the Other Options Are Wrong

A attaches a deny to the Research Administrator permission set. Several commenters, including MrTizz and teo2157, argued this is the more precisely scoped choice because it restricts only the research team; it is a reasonable reading, and it does block members who assume that permission set. However, it depends entirely on Identity Center for enforcement and leaves any other principal or credential path in the account able to create IAM users, so it does not satisfy the unconditional guarantee the requirement states. B uses a permissions boundary that allows all actions except iam:CreateUser; a boundary caps the maximum permissions a principal can receive but is evaluated with, not above, identity-based policies, making it the wrong tool for an absolute prohibition. D creates a Lambda that deletes IAM users after the fact, which is detection and delayed remediation rather than prevention, and users would exist in the interim. C is the correct answer.

Community Comment Notes

Community was closely split, C (56) versus A (44). The C camp argued that a permission set only constrains its own sessions while an SCP enforces the deny across the entire account and cannot be overridden by AdministratorAccess, matching the AWS-suggested answer. The A camp, notably MrTizz and teo2157, argued the wording restricts only the research team, which the permission set already scopes, so an account-wide SCP would also block unrelated principals. C is the official answer and is the stronger guarantee.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide