How to stop or disable aws config recorder in Control Tower

0

We have control Towel account, In that Control Tower one of account has enabled aws config service from few weeks. We are tying to disable the service but it showing the error as "You do not have suffcient permission to perform this action". As i have the admin level privileges, I'm able to enable and disable the aws config service in other control tower account but this issue was facing in this particular account.

  • Thanks for the comments, I have disabled the config long back ago with your inputs. I just modified the SCP policy and stoped the AWS config.

已提问 1 年前1355 查看次数
3 回答
1
已接受的回答

When you've got full administrator access but are still getting denied, see if there is a Service Control Policy (SCP) attached to the account or organizational unit. Your permissions are the overlap between what the SCP allows/denies and what your IAM policies allow/deny.

When you enable AWS Control Tower, it automatically applies guardrails, including preventing such actions as disabling the AWS Config recorder, which makes sense since that is an important tool for maintaining compliance.

AWS
debbie
已回答 1 年前
profile picture
专家
已审核 9 天前
0

This is a mandatory preventative control as a part of Control Tower implemented via an SCP.

profile pictureAWS
专家
kentrad
已回答 1 年前
0

Is the operation prevented by the SCP?
Check the SCP of the OU to which the account belongs.
If guardrails are set up on the control tower, they may be rejected by SCP.
https://docs.aws.amazon.com/controltower/latest/userguide/mandatory-controls.html

profile picture
专家
已回答 1 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则