- Home
- All questions
- Question 21
AWS Certified Solutions Architect study material · question 21 of 500
An administrator removes the FullAWSAccess policy from an organizational unit without attaching any other allow policy. What is the result for member accounts in that OU?
Show the answer
Answer: D. Every AWS action from those accounts fails
SCPs grant nothing, so removing the only allow policy leaves no permitted actions and every call from those accounts is refused.
Source: Service control policies (SCPs) (Amazon Web Services) — Testing effects of SCPs — Note