How to stop or disable aws config recorder in Control Tower

0

We have control Towel account, In that Control Tower one of account has enabled aws config service from few weeks. We are tying to disable the service but it showing the error as "You do not have suffcient permission to perform this action". As i have the admin level privileges, I'm able to enable and disable the aws config service in other control tower account but this issue was facing in this particular account.

  • Thanks for the comments, I have disabled the config long back ago with your inputs. I just modified the SCP policy and stoped the AWS config.

已提問 1 年前檢視次數 1355 次
3 個答案
1
已接受的答案

When you've got full administrator access but are still getting denied, see if there is a Service Control Policy (SCP) attached to the account or organizational unit. Your permissions are the overlap between what the SCP allows/denies and what your IAM policies allow/deny.

When you enable AWS Control Tower, it automatically applies guardrails, including preventing such actions as disabling the AWS Config recorder, which makes sense since that is an important tool for maintaining compliance.

AWS
debbie
已回答 1 年前
profile picture
專家
已審閱 9 天前
0

This is a mandatory preventative control as a part of Control Tower implemented via an SCP.

profile pictureAWS
專家
kentrad
已回答 1 年前
0

Is the operation prevented by the SCP?
Check the SCP of the OU to which the account belongs.
If guardrails are set up on the control tower, they may be rejected by SCP.
https://docs.aws.amazon.com/controltower/latest/userguide/mandatory-controls.html

profile picture
專家
已回答 1 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南