What is the MOST efficient way to design an architecture to meet these requirements?

1 Comment

  1. Ronald
    Author

    In my opinion, the answer is:
    Create an IAM role named procurement-manager-role in all the shared services accounts in the organization. Add the AWSPrivateMarketplaceAdminFullAccess managed policy to the role. Create an organization root-level SCP to deny permissions to administer Private Marketplace to everyone except the role named procurement-manager-role. Create another organization root-level SCP to deny permissions to create an IAM role named procurement-manager-role to everyone in the organization.

Leave a Reply

Your email address will not be published. Required fields are marked *

eight + 10 =