AWS Organizations binds many accounts under one management account. That structure is a pivot: the management account holds a default role into every member, and it sets the service control policies that bound them all. Reaching the management account, or an account that can assume into others, cascades across the estate.
Pages#
- Member account role: assuming the default OrganizationAccountAccessRole the management account creates in each member.
- SCP manipulation: editing service control policies to lift organization-wide guardrails.