Deny IAM actions for non-administrators with a service control policy at the root
A company uses AWS Organizations to manage its AWS accounts. A solutions architect must design a solution in which only administrator roles are allowed to use IAM actions. However, the solutions architect does not have access to all the AWS accounts throughout the company. Which solution meets these requirements with the LEAST operational overhead?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A service control policy attached at the root organizational unit is inherited by every account, so a single statement denying IAM actions except for administrator roles enforces the requirement organization-wide without the architect ever entering an individual account.
A company manages many accounts with AWS Organizations and must ensure that only administrator roles are allowed to perform IAM actions. The architect cannot access every account in the company, so the control has to be applied centrally.
Writing an SCP that allows IAM actions for administrator roles. An SCP does not grant permissions, it only filters what the account can do, so an allow statement cannot be used to grant access that an identity policy has not already granted. A permissions boundary is likewise a maximum, not a grant.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A service control policy attached to the root organizational unit is inherited by every account in the organization, which is the only way to enforce the control without access to each individual account. The policy explicitly denies the IAM actions for all principals except those with an administrator role, using a condition on the principal's role or path, and an explicit deny cannot be overridden by any identity policy in the account. That gives preventive enforcement at the organization level, so the requirement is met centrally and the operational overhead is a single policy to maintain.Why the Other Options Are Wrong
A: An SCP that allows IAM actions only for administrators does not grant those actions. SCPs are permission filters evaluated after the identity policy grants, and an SCP cannot add permissions, so an allow statement changes nothing unless the deny is expressed as an explicit deny. B: Invoking Lambda from CloudTrail on every IAM action is a detective control that reacts after an action has already been recorded, and CloudTrail delivers events on a delay, so it cannot prevent unauthorized IAM changes and it requires operating a Lambda function on an event stream. D: An IAM permissions boundary sets the maximum permissions an identity can have and must be attached to every administrator role in every account, which requires exactly the per-account access the architect does not have.Community Comment Notes
The community voted 100 to 0 for C, and the top-voted comment captured the three traps precisely: SCPs do not allow, they deny; the Lambda on CloudTrail approach is reactive rather than preventive; and permissions boundaries do not allow, they set maximum permissions. A second commenter noted the ambiguity between A and C, explaining that an SCP deny implicitly blocks everything not allowed, which is why the explicit deny form in C is the correct one.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →