Which option ensures that services are not allowed within the production accounts, yet are allowed in separate development accounts within the LEAST administrative overhead?

1 Comment

  1. Judy
    Author

    As far as I’m aware, the answer is:
    Apply service control policies to the AWS Organizational Unit (OU) containing the production accounts to whitelist certified services. Apply a less restrictive policy to the OUs containing the development accounts.

Leave a Reply

Your email address will not be published. Required fields are marked *

17 − 10 =