A policy that restricts, organization-wide, which services and actions the accounts under AWS Organizations are allowed to use.
While individual IAM policies work by stacking up "allow" permissions, an SCP acts as a guardrail defining an absolute upper limit that can never be exceeded. Even if an action is allowed by an IAM policy, it cannot be performed if it's denied by an SCP.
© 2026 ITBGM