Q: Your company uses AWS Organizations. You log in as the absolute overarching Root User of a member account and try to delete a CloudTrail log, but you violently receive an `Access Denied` error. How is the Root User denied permission?
This is the immense power of Service Control Policies (SCPs) administered from the AWS Organizations Management (Master) account.
#AWS #Cost & Architecture #L2 #Cloud #Infrastructure #IAM
🎙️ Candidate Opening & Architectural Context
""In our AWS cloud environment, we managed high-traffic microservices where this exact scenario occurred. The interviewer is testing: Service Control Policies (SCPs) overriding Root.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
This is the immense power of Service Control Policies (SCPs) administered from the AWS Organizations Management (Master) account. An SCP operates as an invisible, overarching boundary. If an SCP applied at the Organization or OU level possesses an explicit Deny for cloudtrail:DeleteTrail, it forcefully supersedes everything below it. It mathematically strips that permission away from *every* entity inside the member account—expressly including the usually omnipotent Root User and Administrator IAM Roles. Only the supreme administrators of the overarching Management Account can alter the SCP.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: This is the immense power of Service Control Policies (SCPs) administered from the AWS Organizations Management (Master) account.."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: This is the immense power of Service Control Policies (SCPs) administered from the AWS Organiza
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement