How to Stop AWS Member Accounts from Leaving Your Organization
As organizations scale their AWS usage across multiple teams, they often consolidate accounts under AWS Organizations for unified billing, governance, and security. However, member accounts can leave the organization just as easily as they joined, potentially stripping away all centrally enforced security controls. To mitigate this, AWS experts recommend a layered defense: restricting the IAM permissions 'organizations:LeaveOrganization' and 'account:CloseAccount' at the user level, and enforcing a Service Control Policy (SCP) at the organization's root level to block these actions across all accounts. AWS Organizations created via the console after July 10, 2026 will automatically include such an SCP, but organizations set up before that date or via API must configure it manually.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in