Deny IAM actions for non-administrators with a service control policy at the root

Answer Correct answer: C — Attach an SCP to the root OU that explicitly denies IAM actions for all principals except administrator roles.

A company uses AWS Organizations to manage its AWS accounts. A solutions architect must design a solution in which only administrator roles are allowed to use IAM actions. However, the solutions architect does not have access to all the AWS accounts throughout the company. Which solution meets these requirements with the LEAST operational overhead?

  1. Create an SCP that applies to all the AWS accounts to allow IAM actions only for administrator roles. Apply the SCP to the root OU.
  2. Configure AWS CloudTrail to invoke an AWS Lambda function for each event that is related to IAM actions. Configure the function to deny the action if the user who invoked the action is not an administrator.
  3. Create an SCP that applies to all the AWS accounts to deny IAM actions for all users except for those with administrator roles. Apply the SCP to the root OU. Correct Answer
  4. Set an IAM permissions boundary that allows IAM actions. Attach the permissions boundary to every administrator role across all the AWS accounts.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A service control policy attached at the root organizational unit is inherited by every account, so a single statement denying IAM actions except for administrator roles enforces the requirement organization-wide without the architect ever entering an individual account.

A company manages many accounts with AWS Organizations and must ensure that only administrator roles are allowed to perform IAM actions. The architect cannot access every account in the company, so the control has to be applied centrally.

Writing an SCP that allows IAM actions for administrator roles. An SCP does not grant permissions, it only filters what the account can do, so an allow statement cannot be used to grant access that an identity policy has not already granted. A permissions boundary is likewise a maximum, not a grant.

Community Discussion (6 comments)

Dgix 👍 5 Selected: C
A: SCPs don't allow, they deny B: is reactive, not preventive C: is correct D: Boundary Permissions don't allow, they set maximum permissions.
Spike2020 👍 1 Selected: C
I will go with C. But between A & C it is very confusing. You can understand the question that SCP deny actions by default and hence you need to allow actions, or if you are white listing you need to deny actions explicitly.
AzureDP900 👍 1
Option C involves creating an SCP that denies IAM actions for all users except those with administrator roles. This approach ensures that only administrators can perform IAM actions, meeting one of the key requirements. The use of an SCP to deny permissions also provides a more centralized and scalable solution compared to options A or D, which focus on allowing specific permissions for administrators. Applying this SCP to the root OU will ensure it applies to all child OUs and their respective AWS accounts, meeting the requirement of enforcing the policy across multiple accounts.
ff32d79 👍 2
If an SCP allows certain IAM actions specifically for administrator roles or groups, it implicitly denies those actions for all other roles and users in the accounts where the SCP is applied. You do not need to explicitly deny the actions for non-administrator roles and users. The implicit deny happens automatically because SCPs define the maximum permissible permissions. So it is A. With C at every new role you have to define it. And Administrators by default have in their IAM permission the capacity to do the modifications.
pangchn 👍 3 Selected: C
C using SCP deny
CMMC 👍 3 Selected: C
Applying SCP to the root OU with specified deny rule

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A service control policy attached to the root organizational unit is inherited by every account in the organization, which is the only way to enforce the control without access to each individual account. The policy explicitly denies the IAM actions for all principals except those with an administrator role, using a condition on the principal's role or path, and an explicit deny cannot be overridden by any identity policy in the account. That gives preventive enforcement at the organization level, so the requirement is met centrally and the operational overhead is a single policy to maintain.

Why the Other Options Are Wrong

A: An SCP that allows IAM actions only for administrators does not grant those actions. SCPs are permission filters evaluated after the identity policy grants, and an SCP cannot add permissions, so an allow statement changes nothing unless the deny is expressed as an explicit deny. B: Invoking Lambda from CloudTrail on every IAM action is a detective control that reacts after an action has already been recorded, and CloudTrail delivers events on a delay, so it cannot prevent unauthorized IAM changes and it requires operating a Lambda function on an event stream. D: An IAM permissions boundary sets the maximum permissions an identity can have and must be attached to every administrator role in every account, which requires exactly the per-account access the architect does not have.

Community Comment Notes

The community voted 100 to 0 for C, and the top-voted comment captured the three traps precisely: SCPs do not allow, they deny; the Lambda on CloudTrail approach is reactive rather than preventive; and permissions boundaries do not allow, they set maximum permissions. A second commenter noted the ambiguity between A and C, explaining that an SCP deny implicitly blocks everything not allowed, which is why the explicit deny form in C is the correct one.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide