A logistics enterprise acquires a regional delivery partner and moves the partner's standalone AWS account into the enterprise's AWS Organizations structure. The enterprise organization uses consolidated billing and has a Service Control Policy (SCP) at the root level that denies access to Amazon Redshift. The partner account contains active EC2 Reserved Instances (RIs) and has an IAM administrator user who needs to manage an existing Amazon Redshift cluster. Which of the following describes the immediate impact of this integration on the partner account's billing and service access?
- The partner account's billing is consolidated under the enterprise, its EC2 usage qualifies for the enterprise's volume pricing discounts, and the IAM administrator is immediately blocked from accessing Amazon Redshift.Cevap
- BThe partner account maintains independent billing until the end of the month, and the IAM administrator can still access Amazon Redshift because SCPs do not override local administrator permissions.
- CThe partner account's billing is consolidated immediately, but its active Reserved Instances cannot be shared with the enterprise, and the Redshift restriction only applies if the account is placed in a custom Organizational Unit (OU).
- DThe partner account's billing remains separate under the AWS Shared Responsibility Model, and the enterprise must use IAM policies in the management account to block Amazon Redshift access on the member account.
Cevap
The partner account's billing is consolidated under the enterprise, its EC2 usage qualifies for the enterprise's volume pricing discounts, and the IAM administrator is immediately blocked from accessing Amazon Redshift.
Upon joining an AWS Organization, a member account's billing immediately consolidates under the organization's management account. This allows the organization to benefit from aggregated volume pricing discounts and share existing Reserved Instances. At the same time, any Service Control Policies (SCPs) applied at the organization's root or OUs act as permission guardrails that filter the account's permissions. Because the root SCP denies access to Amazon Redshift, this restriction immediately overrides any local IAM permissions, blocking the administrator user from managing the Amazon Redshift cluster.
Adım Adım Çözüm
Anahtar Kavram
AWS Organizations Consolidated Billing and Service Control Policies (SCPs)
Tahmini Süre:2m 0s