Which solution will meet these requirements with the LEAST operational overhead?

2 Comments

  1. Larry
    Author

    As I recall, the answer is:
    Create an SCP and a permissions boundary for IAM roles. Add the SCP to the root OU so that only roles that have the permissions boundary attached can create any new IAM roles.

  2. Dennis
    Author

    I assess that the answer is:
    Create an SCP and a permissions boundary for IAM roles. Add the SCP to the root OU so that only roles that have the permissions boundary attached can create any new IAM roles.

Leave a Reply to Dennis Cancel reply

Your email address will not be published. Required fields are marked *

5 × 2 =