Attach an SCP that denies service access to the member-account root user
A company has many member accounts in an organization in AWS Organizations. The company is concerned about the potential for misuse of the AWS account root user credentials for member accounts in the organization. To address this potential misuse, the company wants to ensure that even if the account root user credentials are compromised the account is still protected. Which solution will meet this requirement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
An SCP with an explicit deny bound to the root user is the only control that actively prevents root-user actions org-wide; root cannot detach or override an SCP because SCPs sit above identity-based policies. EventBridge detection (D) only alerts after the fact; removing the password (B) or deleting access keys (C) reduces exposure but is not centrally enforced and does not stop a compromised root from other vectors.
To protect member accounts even if root credentials are compromised, attach an SCP to the OU that uses an explicit deny on the root user's actions (e.g., a deny on all services for the root-user principal). SCPs are evaluated above all other policies and cannot be overridden—even by the root user—so the compromised root user loses its effective permissions.
Choosing EventBridge detection (D)—it notifies that root was used but does not prevent misuse. Deleting access keys (C) or removing the password (B) helps but is per-account, manual, and incomplete (root can still assume roles or reset MFA); an SCP guardrail is centrally enforced and comprehensive.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.