Core Concepts
- Organizational units group accounts for policy and administration.
- SCPs define permission guardrails but do not grant permissions.
- Delegated administrators reduce dependency on the management account.
- Consolidated billing provides organization-wide cost visibility.
Exam Cues
- Need a governed landing zone: Control Tower.
- Need account-level blast-radius isolation: separate AWS accounts.
- Need deny a service across an OU: SCP explicit deny.
- Need central security findings: delegated admin with Security Hub or GuardDuty.
Practice Organizations Questions
Put your knowledge to the test with practice questions.