Skip to content

AWS Technologies Blog

Menu
  • Home
  • KB
  • Services
  • Resources
  • Posts
  • Find
    • Categories
    • Tags
  • About
Menu

Notes for AWS Organizations

Posted on February 25, 2025March 3, 2025 by wpadmin

Policy Boundary vs SCP

FeatureIAM Policy BoundaryService Control Policies (SCPs)
ScopeApplied to individual IAM users/rolesApplied to all IAM users/roles within an AWS account or organization
FunctionDefines maximum allowable permissions for a user or roleRestricts permissions for all IAM users/roles in an account or organizational unit
GranularityGranular, tied to individual roles or usersOrganizational-wide or account-wide control
EffectLimits permissions within the user or role’s own policiesLimits all IAM roles and users within an account or organization, regardless of their individual policies
Use caseRestrict what users/roles can do, even if they have permissions granted elsewhereControl the broad permission levels for multiple accounts in an organization

In summary:

  • IAM Policy Boundaries control the maximum permissions for individual IAM users/roles.
  • Service Control Policies (SCPs) control permissions at the organization or account level, applying guardrails for all IAM users/roles in the scope of an AWS Organization.

  • Product List
  • Documentation

billing ciem containers cost cspm ebs ec2 ecs edge eks elb event Firewall fsx hybrid iam lambda NACL outpostd policies pop princing rds route53 s3 security serverless services SG siem storage vpc

  • Amazon FSx
  • aws
  • aws notes
  • billing
  • cloud
  • compute
  • containers
  • core
  • databases
  • development
  • ebs
  • ec2
  • ecs
  • edge
  • efs
  • eks
  • hybrid
  • iam
  • lambda
  • network
  • outposts
  • pricing
  • rds
  • route53
  • s3
  • security
  • serverless
  • services
  • storage
  • support
  • vpc
©2025 AWS Technologies Blog | Built using WordPress and Responsive Blogily theme by Superb