If you have been honored to rotate 200+ (and growing) ROOT credentials every 90 days to keep auditors happy. With this control, you only need to maintain 1 ROOT credential. Happy days are here again!
Here's your starting point of SCP journey:
Example service control policies https://docs.aws.amazon.com/organizat...
The policy I used was inspired by "Block service access for the root user".