AWS Organization
- global service
controlover multiple AWS accountsconsolidated billing- shared reserved instances and savings plans across accounts ## service control policies (SCPs)
- IAM policy applied to OU or account except management account


IAM role vs Resource-based policy
- IAM role:
cross-accountaccess - Resource-based policy:
cross-serviceaccess
IAM Permission boundaries
- supported for users and roles(not groups)
- maximum permissions that an entity can have
IAM policy+permission boundary=effective permissions
AWS IAM Identity center (AWS Single Sign-On)
AWS Directory Service
AD Connector: on-premises AD, redirect to on-premises AD (proxy)Simple AD: standalone ADAWS Managed Microsoft AD: managed AD, trust relationship