Deny iam:CreateUser with an SCP attached to the research team's account
A cloud team uses AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On) to manage a company's AWS accounts. The company recently established a research team. The research team requires the ability to fully manage the resources in its account. The research team must not be able to create IAM users. The cloud team creates a Research Administrator permission set in IAM Identity Center for the research team. The permission set has the AdministratorAccess AWS managed policy attached. The cloud team must ensure that no one on the research team can create IAM users. Which solution will meet these requirements?
Community Votes
56% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement is a guarantee that user creation is impossible for the team, not merely a reduction in what the permission set grants. An SCP is an explicit deny evaluated above identity-based policies, so it cannot be overridden by the AdministratorAccess managed policy, and it applies to all principals in the member account including root (C). Option A attaches a deny to the permission set, which does stop members using that permission set but leaves any other principal or credential path in the account able to create users; option B uses a permissions boundary, which caps maximum permissions rather than denying an action outright.
The Research Administrator permission set grants AdministratorAccess, and the requirement is that no one on the research team can create IAM users. A deny on iam:CreateUser cannot be overridden by any allow, so attaching an SCP with that deny to the research team's account creates an organizational guardrail that the AdministratorAccess policy cannot bypass, and it covers every principal operating in that account regardless of how they authenticate.
Attaching a deny policy to the permission set (A)—while this blocks members who assume the Research Administrator permission set, it does not cover other principals or access paths in the account, so it does not deliver the unconditional guarantee the requirement asks for. Using a permissions boundary that allows everything except iam:CreateUser (B)—a boundary caps the maximum permissions of a principal but is a delegation-limits feature evaluated alongside identity policies; the SCP deny is the harder organizational guardrail that AdministratorAccess cannot override.
Community Discussion (17 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A service control policy that explicitly denies iam:CreateUser creates an organizational guardrail whose deny takes precedence over any identity-based allow, including the AdministratorAccess managed policy attached to the permission set, because effective permissions are the intersection of what identity-based policies allow and what the SCP permits. AWS documentation also confirms that SCPs affect all users and roles in the attached member account, including the root user, so attaching the SCP to the research team's account makes the prohibition unconditional for everyone operating there. This is the AWS-suggested answer for this item.Why the Other Options Are Wrong
A attaches a deny to the Research Administrator permission set. Several commenters, including MrTizz and teo2157, argued this is the more precisely scoped choice because it restricts only the research team; it is a reasonable reading, and it does block members who assume that permission set. However, it depends entirely on Identity Center for enforcement and leaves any other principal or credential path in the account able to create IAM users, so it does not satisfy the unconditional guarantee the requirement states. B uses a permissions boundary that allows all actions except iam:CreateUser; a boundary caps the maximum permissions a principal can receive but is evaluated with, not above, identity-based policies, making it the wrong tool for an absolute prohibition. D creates a Lambda that deletes IAM users after the fact, which is detection and delayed remediation rather than prevention, and users would exist in the interim. C is the correct answer.Community Comment Notes
Community was closely split, C (56) versus A (44). The C camp argued that a permission set only constrains its own sessions while an SCP enforces the deny across the entire account and cannot be overridden by AdministratorAccess, matching the AWS-suggested answer. The A camp, notably MrTizz and teo2157, argued the wording restricts only the research team, which the permission set already scopes, so an account-wide SCP would also block unrelated principals. C is the official answer and is the stronger guarantee.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →