0PricingLogin
AWS Security Academy · Lesson

Organizations, OUs, and SCP Strategy

Structure accounts and choose allow-list or deny-list SCPs.

Governing Many Accounts

AWS Organizations lets you centrally manage many AWS accounts as one structure. Within it, Service Control Policies (SCPs) set permission ceilings, and Organizational Units (OUs) group accounts for policy targeting. Designing this hierarchy well is a core skill for the SCS-C02 exam's governance domain.

The Organization Structure

An organization has a management account (formerly master) at the top, a root container, and OUs that can nest to group member accounts. Policies attached at any level flow down to everything beneath. This tree lets you apply controls broadly or narrowly with one attachment.

All lessons in this course

  1. What a Permission Boundary Limits
  2. Delegating Role Creation Safely
  3. Organizations, OUs, and SCP Strategy
  4. How SCPs Combine with IAM Permissions
← Back to AWS Security Academy