Guardrail: Deny access to AWS based on the requested AWS RegionInfo - how to customize the Guardrail SCP??

0

Hello if you use the Region deny option in AWS Control Tower ist set the Guardrail: Deny access to AWS based on the requested AWS RegionInfo. In this Guardrail the SCP is missing the global Service "Artifact" in the SCP Part "Resource": "*", "Effect": "Deny", "NotAction": [.... How can i customize this SCP?

1 個回答
2

Hi, I believe the best way to do that is with your own custom SCP deployment rather than use the Region Deny setting in Control Tower, as it can't be modified. You can use the same template that Control Tower uses via this link. And deploy it via your own processes, which may use Customizations for Control Tower, Account Factory for Terraform or other infrastructure as code process.

profile pictureAWS
已回答 2 年前
  • I opened a case and the customer support created a request at the internal team but for now just custom SCP or deactivation as workaround is possible.

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南