Open
Description
When an account is in the Suspended OU, ALL actions including IAM are blocked. This prevents anyone from logging into the account, it has to be moved back to the Workloads OU using the CI that assumes the ControlTower role. Adding this role/rolename property to be excluded from the SCP that blocks all actions will allow an admin to access it if needed.