Organizations, SCPs & Control Tower
AWS for Interviews: lesson 16 of 18
SCPs set the ceiling for every account below them; IAM still has to grant.
Lesson 16 of 18 · 7 min
Organizations, SCPs & Control Tower
Step 1 of 10
One organization: the root, a Workloads OU, a prod account inside it. SCPs are attached at each level.
The Idea
Organizations groups accounts into OUs under one root. SCPs set the maximum permissions for users and roles in member accounts; they grant nothing and skip the management account. An action must be allowed at every level, root to account, and still needs an IAM or resource policy allow; an explicit Deny anywhere wins. Control Tower builds a governed landing zone, and delegated administrators run services like GuardDuty from a member account.
Real-World Example
A Workloads OU carries an SCP that denies stopping CloudTrail. A developer with AdministratorAccess in the prod account tries anyway and is denied. A security account is the delegated administrator for GuardDuty.
The Tradeoff
A wrong SCP on the root can lock every account out, so test it on a small OU first. SCPs never touch the management account — keep it nearly empty.
Hands-On
{
"Version": "2012-10-17",
"Statement": [{
"Sid": "NoTrailTampering",
"Effect": "Deny",
"Action": ["cloudtrail:StopLogging", "cloudtrail:DeleteTrail"],
"Resource": "*"
}]
}
Your turn
Order how AWS evaluates a request inside one member account.
- Check the SCPs: every level from the root to the account must allow the action
- Look for an explicit Deny in every policy that applies
- Check identity-based policies for an Allow
- Check the resource-based policy
Mini quiz
1 / 3
A role in a member account has AdministratorAccess. Its OU's SCP denies cloudtrail:StopLogging. The role calls StopLogging:
Sources
- Service control policies (SCPs) — AWS Organizations User Guide
- How AWS enforcement code logic evaluates requests to allow or deny access — AWS Identity and Access Management User Guide
- How controls work — AWS Control Tower User Guide
- Delegated administrator for AWS services that work with Organizations — AWS Organizations User Guide