1 個回答
- 最新
- 最多得票
- 最多評論
1
Is your account a member account in a AWS Organization and is it possible there's a SCP in place? "An SCP restricts permissions for IAM users and roles in member accounts, including the member account's root user. Any account has only those permissions permitted by every parent above it. If a permission is blocked at any level above the account, either implicitly (by not being included in an Allow policy statement) or explicitly (by being included in a Deny policy statement), a user or role in the affected account can't use that permission, even if the account administrator attaches the AdministratorAccess IAM policy with / permissions to the user."
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
已回答 2 個月前
相關內容
- 已提問 1 年前
Thank you! This is very helpful and makes sense, but where do I go to actually see if an SPC is denying the policy even in my root/admin accounts? Is there a specific setting? I followed your link to the articles, but I'm struggling with finding out how to correct the permissions. Thank you!!
Hi AlexC. Access the SCPs from the AWS Organizations console. The steps are here [1].
[1] https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_create.html
Hi, Jose! Thanks for your response. When I click "Organization" (upper right-hand side of the screen), I get a page about what organizations are. On the left-hand side of that page is an option for "Invitations." I click on that and it says there are no invitations. I don't think I have any organizations assigned to any of my accounts (root or admin).
Hi, there! I'm still really struggling with this. Can I get additional direction and ideas as to what to do? Thank you!
Jose- I used Incognito to access the portal. I went to:
Billing and Cost Management
Here is the text: User: [my user account number is here] Service: [Cost Explorer] Name: [AccessDeniedException] HTTP status code: [400] Context: [IAM user access not activated] Request ID: [this is a unique number I didn't want to cut/paste into this message]
Any thoughts? Thanks again for your help!