Which option will allow administrators to make changes and continue to enforce the current policies without introducing additional long-term maintenance?

1 Comment

  1. Deborah
    Author

    My best guess is:
    Create a temporary OU named Onboarding for the new account. Apply an SCP to the Onboarding OU to allow AWS Config actions. Move the organization’s root SCP to the Production OU. Move the new account to the Production OU when adjustments to AWS Config are complete.

Leave a Reply

Your email address will not be published. Required fields are marked *

19 + 17 =