Skip to content

Latest commit

 

History

History

Organizations

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 

Notes

  • Enforcing enterprise-wide preventive controls with AWS Organizations, AWS, 2025-01-09
    • Service control policy (SCP)
      • Governs: IAM principals (within your organization)
      • Usage: Restrict the permissions of IAM principals in member accounts of your organization.
      • Considerations:
        • SCPs don’t affect IAM principals from accounts outside your organization.
        • SCPs affect requests to resources that live in accounts outside of your organization.
    • Resource control policy (RCP)
      • Governs: AWS resources (within your organization)
      • Usage: Control access to resources within your organization by IAM principals external to your organization.
      • Considerations:
        • RCPs affect IAM principals from all accounts, even those outside of your organization.
        • RCPs don’t affect requests to resources that live in accounts outside of your organization.
    • Declarative policy
      • Governs: Service configuration
      • Usage: Ensure consistent and compliant configurations for AWS services across your organization.

RCP (Resource Control Policy)

SCP (Service control policy)