Use cases for Delegated Administrator for AWS Organizations
ID: 7f35901e-5554-5bc7-b42c-b23fb943a6cb
STIX ID: report--7f35901e-5554-5bc7-b42c-b23fb943a6cb
Feed Name: Wiz Blog
This post explains AWS’s new delegated administrator for AWS Organizations, which enables selective delegation of Org capabilities such as viewing account metadata and managing policy types (SCPs, backup policies, tag policies, and AI services opt-out) to member accounts. It outlines practical use cases (e.g., account/owner visibility, viewing effective SCPs, delegating SCP updates per OU), provides sample delegation policies and a Python script for SCP discovery, and highlights governance and security caveats, including the risk of inconsistent controls and potential protection gaps with deny-list SCP strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
