Guardrail: Deny access to AWS based on the requested AWS RegionInfo - how to customize the Guardrail SCP??


Hello if you use the Region deny option in AWS Control Tower ist set the Guardrail: Deny access to AWS based on the requested AWS RegionInfo. In this Guardrail the SCP is missing the global Service "Artifact" in the SCP Part "Resource": "*", "Effect": "Deny", "NotAction": [.... How can i customize this SCP?

1 Answer

Hi, I believe the best way to do that is with your own custom SCP deployment rather than use the Region Deny setting in Control Tower, as it can't be modified. You can use the same template that Control Tower uses via this link. And deploy it via your own processes, which may use Customizations for Control Tower, Account Factory for Terraform or other infrastructure as code process.

profile pictureAWS
answered 2 years ago
  • I opened a case and the customer support created a request at the internal team but for now just custom SCP or deactivation as workaround is possible.

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions