1
Identity and Access Management
medium
A company uses AWS Organizations with all features enabled. A security engineer has applied a Service Control Policy (SCP) at the Organizational Unit (OU) level that explicitly denies the 'iam:CreateUser' action. However, a specific IAM user in a member account within that OU has an administrator policy attached. What is the resulting behavior when this user attempts to create a new IAM user?