Find answers, ask questions, and connect with our
community around the world.

Home Forums AWS AWS Certified Solutions Architect Professional Fundamental Error in Question on SCP Allow Inheritance Reply To: Fundamental Error in Question on SCP Allow Inheritance

  • Jayid

    Member
    April 30, 2026 at 11:30 pm

    Based on your logic, we should be able to create the bucket because the account is already inheriting the FullAWSAccess SCP from Root and Sandbox OU. However, the account itself does not have the FullAWSAccess SCP attached. So going back to the documentation:

    For a permission to be allowed for a specific
    account, there must be an explicit allow statement at every level from the root through each OU in the direct path
    to the account (including the target account itself).

    The question does not explicitly say anything about the SCPs attached to the account level. So we can’t rule out misconfigured SCP as a potential issue.

    • This reply was modified 1 month, 2 weeks ago by  Jayid.
Skip to content