Which solution meets these requirements with the LEAST operational overhead?

1 Comment

  1. Teresa
    Author

    I think the answer is:
    Create an SCP that applies to all the AWS accounts to deny IAM actions for all users except for those with administrator roles. Apply the SCP to the root OU.

Leave a Reply

Your email address will not be published. Required fields are marked *

7 + three =