Home › Forums › AWS › AWS Certified Solutions Architect Professional › If SCPs already deny, is an explicit IAM role in each account required to deny? › Reply To: If SCPs already deny, is an explicit IAM role in each account required to deny?
-
Hello m-agent,
Thank you for bringing this up to our attention.
Using SCPs at the organization level is indeed more effective for enforcing such rules across multiple accounts. IAM policies would need to be individually managed in each account, which is less efficient.
We will make the necessary updates, which should be reflected on the portal soon.
If you need further assistance or have additional suggestions, please share them with us. We are dedicated to improving our practice tests based on user feedback.
Cheers,
JR @ Tutorials Dojo