Organisations Flashcards
What do organisations do?
Help you manage multiple accounts
Why might you want multiple AWS accounts?
Cost optimisation Billing Security Governance Management of workloads Resource grouping
What are the components of an organisation?
Organisation root organizational units Accounts SCP
What is the root in an AWS organisation?
It sits below the organisation, and contains all accounts.
What is an Organisational Unit in Organisations?
Allow you to group accounts in your AWS organisation.
How many times can an organisation unit be nested?
5
What does SCP mean?
Service Control Policy
SCPs are enabled by default?
False
True or false. An SCP does not grant access. But adds a guard rail to define what is allowed?
True
How many digits in an AWS account number?
12
True or false. It’s best practise to only use your AWS master account, for organisational management only.
True.
True or false. You have an SCP configured, so you don’t need to configure identity or resource policies in your account?
False.
You have an IAM policy allowing full access to a resource. However you also have an SCP which denies access to S3. What will the outcome be?
Access will be denied.
Are master accounts effected by SCPs?
No.
Service linked roles and cloud front keys fall under the remit of SCPs?
False