Which solution will meet these requirements with the LEAST operational overhead?

1 Comment

  1. Larry
    Author

    As I recall, the answer is:
    Create an SCP and a permissions boundary for IAM roles. Add the SCP to the root OU so that only roles that have the permissions boundary attached can create any new IAM roles.

Leave a Reply

Your email address will not be published. Required fields are marked *

3 × 4 =