Organizations, OUs, and SCP Strategy
Structure accounts and choose allow-list or deny-list SCPs.
Governing Many Accounts
AWS Organizations lets you centrally manage many AWS accounts as one structure. Within it, Service Control Policies (SCPs) set permission ceilings, and Organizational Units (OUs) group accounts for policy targeting. Designing this hierarchy well is a core skill for the SCS-C02 exam's governance domain.
The Organization Structure
An organization has a management account (formerly master) at the top, a root container, and OUs that can nest to group member accounts. Policies attached at any level flow down to everything beneath. This tree lets you apply controls broadly or narrowly with one attachment.
All lessons in this course
- What a Permission Boundary Limits
- Delegating Role Creation Safely
- Organizations, OUs, and SCP Strategy
- How SCPs Combine with IAM Permissions