How AWS Organizations SCPs and Landing Zones Work in Production

AWS Organizations offers more than consolidated billing — its real value lies in a hierarchical control plane that applies guardrails across all accounts in an organization. The structure consists of a management account, a root, nested organizational units (OUs), and member accounts where workloads actually run. Service Control Policies (SCPs) and Resource Control Policies (RCPs) set maximum permission boundaries but grant nothing on their own, and a common source of confusion is that Allow permissions must be explicitly present at every level from root down to the account. A missing Allow at any OU level results in an implicit deny, even if an IAM policy inside the account grants full access. Teams building a landing zone are advised to enable all features — not just consolidated billing mode — and to design OUs around lifecycle and control needs rather than organizational structure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in