Guardrail: Deny access to AWS based on the requested AWS RegionInfo - how to customize the Guardrail SCP??

0

Hello if you use the Region deny option in AWS Control Tower ist set the Guardrail: Deny access to AWS based on the requested AWS RegionInfo. In this Guardrail the SCP is missing the global Service "Artifact" in the SCP Part "Resource": "*", "Effect": "Deny", "NotAction": [.... How can i customize this SCP?

1 回答
2

Hi, I believe the best way to do that is with your own custom SCP deployment rather than use the Region Deny setting in Control Tower, as it can't be modified. You can use the same template that Control Tower uses via this link. And deploy it via your own processes, which may use Customizations for Control Tower, Account Factory for Terraform or other infrastructure as code process.

profile pictureAWS
已回答 2 年前
  • I opened a case and the customer support created a request at the internal team but for now just custom SCP or deactivation as workaround is possible.

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则