Delegated administrator for Amazon Organizations - Amazon Organizations
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Delegated administrator for Amazon Organizations

We recommend that you use the Amazon Organizations management account and its users and roles only for tasks that must be performed by that account. We also recommend that you store your Amazon resources in other member accounts in the organization and keep them out of the management account. This is because security features like Organizations service control policies (SCPs) do not restrict users or roles in the management account.

From the organization's management account, you can delegate policy management for Organizations to specified member accounts to perform policy actions that are by default available only to the management account.

For example resource-based delegation policies, see Resource-based policy examples for Amazon Organizations.