AWS Cloud Intelligence dashboard templates blocked by SCPs ?

0

Trying to implement the AWS Cloud Intelligence Dashboards for my organisation. The data collection steps are all proceeding well, but I am unable to install the dashboards. Regardless of whether using CloudFormation or the cli tool, for some reason the QuickSight templates are returning an "Access Denied" error.

Specifically: *CRITICAL - Error: An error occurred (AccessDeniedException) when calling the DescribeTemplate operation: * <user> not authorized to perform: quicksight:DescribeTemplate on resource: arn:aws:quicksight:us-east-1:223485597511:template/cudos_dashboard_v3 with an explicit deny in a service control policy

Does anyone have any suggestions please ?

Shane H
feita há 10 meses265 visualizações
3 Respostas
1

I would review what SCP's you have in place in your ORG/OU's https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html

If using control tower, you may have turned on some controls which places SCP's into effect to prevent specific actions. There are mandatory controls inplace https://docs.aws.amazon.com/controltower/latest/userguide/mandatory-controls.html

Here is some documentation which also relates to an SCP to block QuickSight https://docs.aws.amazon.com/quicksight/latest/user/security-scp.html

profile picture
ESPECIALISTA
respondido há 10 meses
0

The error you got is typically caused indeed by SCP.

Suggestion is to access or request the account owner/organization to and, modify the explicit SCP deny by allowing your account for instance to perform the quick sight action.

profile picture
ESPECIALISTA
respondido há 10 meses
profile pictureAWS
ESPECIALISTA
avaliado há 10 meses
0

I am getting the same error, i think this is the issue with AWS account which is in below ARN. That account is owned by AWS and its referred by CFN to get some template. as I dont have anything in us-east-1 and below account is not part of my organisation.

arn:aws:quicksight:us-east-1:223485597511:template/cudos_dashboard_v3 with an explicit deny in a service control policy

profile picture
Sagar
respondido há 9 meses

Você não está conectado. Fazer login para postar uma resposta.

Uma boa resposta responde claramente à pergunta, dá feedback construtivo e incentiva o crescimento profissional de quem perguntou.

Diretrizes para responder a perguntas