Home › Forums › AWS › AWS Certified Solutions Architect Professional › If SCPs already deny, is an explicit IAM role in each account required to deny? › Reply To: If SCPs already deny, is an explicit IAM role in each account required to deny?
-
Maybe the 2nd answer choice should be to add IAM role in each account that explicitly allow creation of EC2 instances provided the project tags are included.