Security and multi-account governance form a core pillar of D1 in SAP-C02. Large organizations operate dozens to hundreds of AWS accounts, and managing these accounts under consistent security policies is a primary responsibility of a Solutions Architect.
The key question is "How do you meet this organization's security requirements with minimal operational overhead?" The right combination of SCP, IAM Identity Center, Control Tower, and KMS enables efficient centralized control over hundreds of accounts.
AWS Organizations and SCP
AWS Organizations groups multiple AWS accounts into a single organization. Accounts are organized into OUs (Organizational Units), and Service Control Policies (SCP) are applied to each OU.
The fundamental SCP rule is that Deny always wins. An action denied by SCP cannot be performed regardless of IAM policy permissions. Think of SCP as a boundary layer above IAM.
The management account is exempt from SCP. This is frequently tested. For example, "Block Reserved Instance purchases across all accounts, but allow the finance team to purchase." Applying an SCP at the root OU automatically exempts the management account.
To exempt specific accounts, create a separate OU and move them there. SCP syntax does not support excluding individual accounts by condition.
| SCP Pattern | Description | |-------------|-------------| | Deny at Root OU | Block specific actions org-wide, management account auto-exempt | | Exception OU separation | Move exempt accounts to a separate OU | | Region restriction | Block API calls outside allowed regions | | Service restriction | Block specific services (EC2 purchases, S3 public access, etc.) |
IAM Identity Center (SSO)
IAM Identity Center provides centralized access management across multiple AWS accounts. Users log in once and can access all assigned accounts and roles.
When integrating with external Identity Providers (IdP), SAML 2.0 federation is used. The exam frequently tests that the SAML Assertion Role ARN and IdP ARN must match the IAM Role Trust Policy. If you see an AccessDenied error, check this mapping first.
Permission Sets are bundles of permissions assigned to users through IAM Identity Center. A single Permission Set can be assigned to multiple accounts, enabling consistent permission management across hundreds of accounts.
Control Tower
Control Tower is a landing zone automation service built on top of Organizations. When new accounts are created, predefined security guardrails (SCP + Config Rules) are automatically applied.
There are two types of guardrails. Preventive guardrails use SCP to proactively block specific actions. Detective guardrails use AWS Config Rules to detect and report non-compliant states.
Account Factory is Control Tower's automated account creation feature. It provisions new accounts with standardized settings (VPC, subnets, security groups). It integrates with Service Catalog so development teams can self-service new account requests.
KMS and Cross-Account Encryption
KMS (Key Management Service) centrally manages encryption keys. Cross-account scenarios are frequently tested in SAP-C02.
To decrypt data encrypted with Account A's KMS key from Account B, two configurations are required. The KMS key policy must allow Account B's role, and Account B's IAM policy must allow use of that KMS key.
AWS-managed keys (aws/s3, aws/ebs, etc.) do not support cross-account access. Cross-account scenarios require a Customer Managed Key (CMK).
For S3 bucket encryption, SSE-S3 uses S3-managed keys, while SSE-KMS uses KMS CMK. When accessing S3 cross-account with SSE-KMS, KMS key permissions must also be configured.
CloudTrail and Centralized Logging
Large organizations must collect API call logs from all accounts centrally. Creating an Organizations Trail automatically delivers CloudTrail logs from all accounts in the organization to a designated S3 bucket.
Place the S3 bucket in a central logging account, with a bucket policy allowing CloudTrail writes from all accounts in the organization. Protect this bucket with S3 Object Lock to prevent log tampering.
Security Hub aggregates security findings from GuardDuty, Inspector, Config, and other sources. Designating a Delegated Administrator allows a dedicated security account (not the management account) to monitor the security posture of the entire organization.
RAM — Resource Sharing
AWS RAM (Resource Access Manager) shares resources across accounts within an organization. You can share Transit Gateways, Resolver Rules, subnets, License Manager configurations, and more.
With Organizations integration enabled, sharing at the OU level is possible, so new accounts added to an OU automatically gain access to shared resources.
Exam Key Points
"Block specific actions across all accounts, no exceptions" -- SCP (except management account)
"Management account is not affected by SCP" -- SCP management account exemption rule
"Exempt only specific accounts" -- Move to separate OU, do not apply SCP to that OU
"SSO access across multiple accounts" -- IAM Identity Center
"SAML federation AccessDenied" -- Check Role ARN/IdP ARN mapping
"Automatic security guardrails for new accounts" -- Control Tower
"Cross-account encrypted data access" -- Customer Managed CMK + key policy + IAM policy
"Cross-account access with AWS-managed key" -- Not possible. CMK required
"Org-wide API audit logs" -- Organizations Trail (CloudTrail)
"Centralized security findings aggregation" -- Security Hub + Delegated Administrator
"Share resources within organization" -- AWS RAM