1 Answer
- Newest
- Most votes
- Most comments
0
Am I allowed to assume the role or prohibited by the applied GuardRails.
That depends what's in the GuardRails (by which I'm guessing you mean SCPs) that are applied to the Log Archive Account. You can view these from the AWS Organizations management account in AWS Console -> Organizations -> AWS accounts and then finding the Log Archive account. Look in the Policies tab to see what SCPs are applied.
There's a very in-depth look at AWS Control Tower Execution Roles and how they can (and can't) be assumed here https://docs.aws.amazon.com/controltower/latest/userguide/roles-how.html
Relevant content
asked 3 years ago
- AWS OFFICIALUpdated 2 months ago
