QuestionQ49

Security and Compliance

A company uses AWS Organizations to manage a collection of AWS accounts and has configured organizational units (OUs) in the organization. An application OU supports multiple applications.

A CloudOps engineer must stop users from launching Amazon EC2 instances without a CostCenter-Project tag in any account within the application OU. The restriction must apply only to accounts in the application OU.

Which solution meets these requirements?

Explanation

An SCP attached to an OU sets a permissions boundary for all accounts in that OU. An explicit deny of ec2:RunInstances when aws:RequestTag/CostCenter-Project is absent prevents untagged EC2 instance launches even if an IAM policy otherwise allows them, while targeting only the application OU. AWS documents SCP-based tag enforcement using an explicit deny on ec2:RunInstances and a missing request-tag condition.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!