Join our Newsletter — 33% off our NHI Course

Delegated Administrator

A delegated administrator is an AWS account given authority to manage a specific organization-level service on behalf of the organisation. This reduces dependence on the management account and lets security or platform teams operate services with narrower access and clearer separation of duties.

What a delegated administrator is

A delegated administrator is a service-specific delegation model in AWS, where one account is authorised to administer a particular organisation-wide service without using the management account for every action. The key idea is narrower operational authority with clearer separation of duties.

Why the delegated administrator model exists

This model helps organisations keep the management account highly protected while still allowing platform, security, or compliance teams to run day-to-day service administration. It is useful when a service needs centralised oversight, but not every change should require the root of organisational authority.

In practice, the model reduces concentration of privilege and helps teams assign responsibility to the account that actually operates the service. That separation matters most in larger AWS organisations where control-plane work, service administration, and billing or account governance are intentionally not handled by the same people.

Where delegated administration fits in AWS governance

delegated administration sits between full central control and uncontrolled local autonomy. The management account retains ownership of the organisation, while a delegated administrator manages supported services for member accounts or the whole organisation, depending on the service design.

This structure is often paired with least-privilege design and explicit account boundaries. It does not mean the delegated account can do anything in AWS, only that AWS recognises it as the administrator for a specific service scope.

Because AWS services vary in how delegation works, the exact permissions and trust relationships are service-dependent. Some services support one delegated administrator, some support multiple administrator roles, and some expose only limited delegated functions.

Common failure modes and operational trade-offs

The main trade-off is convenience versus concentration of authority. A delegated administrator can improve speed and separation of duties, but it also creates a high-value control point if the delegated account is over-permissioned, poorly monitored, or shared across teams.

It is also easy to confuse service administration with organisational administration. A delegated administrator should not be treated as a substitute for the management account, and it should not be assumed to inherit every organisation-level permission just because it can administer one service.

When the delegation boundary is unclear, teams may over-trust the account, duplicate duties across accounts, or leave service ownership ambiguous. That can produce governance gaps even when the AWS configuration itself is technically valid.

How to think about the term in security reviews

In a security review, the important question is not simply whether delegation exists, but what exact authority has been delegated, who owns it, and how the delegated scope is restricted. A delegated administrator is strongest when the scope is narrow, the owner is explicit, and the management account remains protected from routine service operations.

For readers comparing this model with broader access concepts, AWS delegated administration is best understood as a governance pattern for a service control plane, not as a general-purpose identity or access mechanism.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Delegated admins are a privileged account-management pattern with scope control.
Recommendation — Limit delegated administrator scope and review privileged accounts routinely.
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Delegated administration narrows authority to a service-specific role boundary.
AC-2 — Account Management The model depends on explicitly creating, tracking, and governing the delegated account.
Recommendation — Assign only the service permissions needed for the delegated function. Track delegated administrator accounts and revoke them when the role changes.
NIST CSF 2.0 PR.AA-05 — Least Privilege and Access Control Delegation is a practical access-control boundary for an organisation-scoped service.
Recommendation — Enforce least privilege for delegated administrator access paths.
ISO/IEC 27001:2022 A.5.15 — Access control Delegated administration is an access-control decision with defined authority limits.
Recommendation — Document and enforce the access scope granted to each delegated administrator.