A. Update the SAML assertion to pass the user’s team name. Update the IAM role’s trust policy to add an access-team session tag that has the team name.
B. Create an approval rule template for each team in the Organizations management account. Associate the template with all the repositories. Add the developer role ARN as an approver.
C. Create an approval rule template for each account. Associate the template with all repositories. Add the “aws:ResourceTag/access-team”: “$ ;{aws:PrincipalTag/access-team}” condition to the approval rule template.
D. For each CodeCommit repository, add an access-team tag that has the value set to the name of the associated team.
E. Attach an SCP to the accounts. Include the following statement:
Most Voted
F. Create an IAM permissions boundary in each account. Include the following statement:

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.