A company has an AWS Control Tower landing zone. The company's DevOps team creates a workload OU. A development OU and a production OU are nested under the workload OU. The company grants users full access to the company's AWS accounts to deploy applications.
The DevOps team needs to allow only a specific management 1AM role to manage the 1AM roles and policies of any AWS accounts In only the production OU.
Which combination of steps will meet these requirements? {Select TWO.)
You need to understand how SCP inheritance works in AWS. The way it works for Deny policies is different that allow policies.
Allow polices are passing down to children ONLY if they don't have an allow policy.
Deny policies always pass down to children.
That's why there is always an SCP set to the Root to allow everything by default. If you limit this policy, the whole organization will be limited, not matter what other policies are saying for the other OUs. So it's not A. It's not D because it restricts the wrong OU.
Catina
3 months agoBerry
3 months agoBen
3 months agoGaynell
4 months agoEarnestine
4 months agoSommer
4 months agoDelmy
4 months agoElli
4 months agoPatria
5 months agoLayla
5 months agoPeggie
5 months agoBilly
5 months agoGracia
5 months agoMarkus
5 months agoLevi
5 months agoAlita
2 years agoElfrieda
2 years agoAlesia
1 year agoMaxima
1 year agoFernanda
2 years agoBrock
2 years agoShawn
2 years agoNorah
2 years agoViki
2 years agoArlene
2 years agoChau
2 years agoChuck
1 year agoSonia
2 years agoYasuko
2 years agoLindsey
2 years agoBrett
2 years agoOlen
2 years agoVi
2 years agoDominque
2 years agoBerry
2 years agoLilli
2 years agoTarra
2 years agoVicky
2 years agoRonnie
2 years agoMaybelle
2 years ago