How to stop or disable aws config recorder in Control Tower

0

We have control Towel account, In that Control Tower one of account has enabled aws config service from few weeks. We are tying to disable the service but it showing the error as "You do not have suffcient permission to perform this action". As i have the admin level privileges, I'm able to enable and disable the aws config service in other control tower account but this issue was facing in this particular account.

  • Thanks for the comments, I have disabled the config long back ago with your inputs. I just modified the SCP policy and stoped the AWS config.

질문됨 일 년 전1355회 조회
3개 답변
1
수락된 답변

When you've got full administrator access but are still getting denied, see if there is a Service Control Policy (SCP) attached to the account or organizational unit. Your permissions are the overlap between what the SCP allows/denies and what your IAM policies allow/deny.

When you enable AWS Control Tower, it automatically applies guardrails, including preventing such actions as disabling the AWS Config recorder, which makes sense since that is an important tool for maintaining compliance.

AWS
debbie
답변함 일 년 전
profile picture
전문가
검토됨 9일 전
0

This is a mandatory preventative control as a part of Control Tower implemented via an SCP.

profile pictureAWS
전문가
kentrad
답변함 일 년 전
0

Is the operation prevented by the SCP?
Check the SCP of the OU to which the account belongs.
If guardrails are set up on the control tower, they may be rejected by SCP.
https://docs.aws.amazon.com/controltower/latest/userguide/mandatory-controls.html

profile picture
전문가
답변함 일 년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠