Q: What is Service Control Policy (SCP) in AWS Organizations and how is it different from an IAM policy?
SCP is a guardrail for entire AWS accounts in an Organization. It restricts what IAM policies in those accounts can allow. If SCP doesn't...
#AWS #Cost & Architecture #L3 #Cloud #Infrastructure #IAM
🎙️ Candidate Opening & Architectural Context
""In a previous role, our monitoring paged me for a similar incident across our AWS VPC infrastructure. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
SCP is a guardrail for entire AWS accounts in an Organization. It restricts what IAM policies in those accounts can allow. If SCP doesn't allow an action, no IAM policy in that account can grant it. SCPs don't grant permissions — they limit the maximum permissions. Use: prevent any account from leaving the org, prevent specific regions from being used, enforce tagging requirements.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: SCP is a guardrail for entire AWS accounts in an Organization. It restricts what IAM policies in those accounts can allow. If SCP ."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: SCP is a guardrail for entire AWS accounts in an Organization. It restricts what IAM policies i
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement