A. Create IAM roles in each account to be used by AWS SSO, and associate users with these roles using AWS SSO.
B. Create IAM users in the master account, and use AWS SSO to associate the users with the accounts they will access.
C. Create permission sets in AWS SSO, and associate the permission sets with Directory Service users or groups.
D. Create service control policies (SCPs) in Organizations, and associate the SCPs with Directory Service users or groups.

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.