Edit the root SCP to add a Condition excluding the marketing account from the external-sharing deny
A company uses an organization in AWS Organizations to manage its AWS accounts. The company has implemented an SCP in the root account to prevent resources from being shared with external accounts. The company now needs to allow applications in its marketing team's AWS account to share resources with external accounts. The company must continue to prevent all the other accounts in the organization from sharing resources with external accounts. All the accounts in the organization are members of the same OU. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
You cannot 'allow' around an SCP deny with another SCP (A's new allow SCP would be overridden by the root deny). The fix is to refine the existing deny with a Condition that carves out the marketing account. An IAM permissions boundary (D) is per-principal and does not override the org SCP. Editing the deny with an exclusion condition (B) is the precise, minimal change. C (adding an Allow) cannot defeat the existing deny.
An SCP at the organization root denies sharing resources with external accounts for all members of one OU, and only the marketing account needs an exception. Because SCPs are deny-by-default and denies cannot be overridden by an Allow, the correct approach is to edit the existing SCP and add a Condition that excludes the marketing account's principal/resource from the deny statement—leaving the restriction in force for every other account.
Creating a new SCP that 'allows' sharing for marketing (A/C)—an Allow cannot overcome the existing root-level Deny, so it would have no effect. Using a permissions boundary (D)—that constrains a principal's max permissions but does not override the organization SCP deny. The right move is a Condition exclusion on the existing deny (B).
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.