All Content tagged with Service Control Policy
Service control policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization.
Content language: English
Filter content
Select tags to filter
Sort by
Sort by most recent
94 results
Rob_HEXPERT
published 15 days ago0 votes258 views
When enforcing zero data retention on Amazon Bedrock with an SCP, there's an important prerequisite: new accounts default to inherit (not none). The SCP prevents changing the mode, but it doesn't set ...
Darius MousazadehEXPERT
published a month ago1 votes183 views
If your organization uses a blanket AI services opt-out policy, opting a single account back in isn't straightforward. The org-wide policy silently blocks child overrides. This article walks through u...
Rahul ASUPPORT ENGINEER
published 2 months ago0 votes186 views
This article provides two Service Control Policies (SCPs) that enforce tagged application inference profiles as the only permitted Bedrock invocation path, enabling organizations to achieve complete g...

We have been hacked and a bad actor has taken over our AWS account. The have instituted a SCP and now we cann...
2
answers
0
votes
81
views
asked 3 months ago
Elvis_PEXPERT
published 3 months ago1 votes294 views
Building an Enterprise Landing Zone
I received a security notice from AWS regarding unauthorized activity on my account. The notice asks me to follow certain remediation steps including checking CloudTrail, rotating access keys, and res...
2
answers
-1
votes
78
views
asked 3 months ago
I am trying to send an outbound WhatsApp message using the StartOutboundChatContact API in Amazon Connect.
API Endpoint:
POST https://connect.us-east-1.amazonaws.com/contact/outbound-chat
Region:
us...
2
answers
0
votes
50
views
asked 4 months ago
I have delegated management of AWS Organizations and Identity Center to a DedicatedAdmin AWS account.
I have setup an identity center group for the Management account. Lets call this group "Mgmt Admi...
2
answers
0
votes
155
views
asked 7 months ago
Ramu VaranasiEXPERT
published 7 months ago0 votes1.1K views
When using Amazon Bedrock with inference profiles in an AWS environment restricted by Control Tower, you may encounter challenges accessing required regions. This article explains how to maintain secu...
Kanwar BajwaEXPERT
published 7 months ago0 votes679 views
Ever worried about accidentally launching expensive AWS resources that blow your budget? This guide shows you how to automatically **prevent new AWS operations** when your spending reaches certain thr...
I tried following the steps: herehttps://repost.aws/questions/QUx25XcQFaQNic0VkqCu3bBw/how-can-i-properly-modify-a-bucket-managed-by-control-tower
However, after creating this role to assume and assi...
5
answers
0
votes
172
views
asked 8 months ago
**Problem:**
I have an S3 bucket that was created and is managed by AWS Control Tower
**Solution:**
I need a solution that will allow me to modify the bucket just to change some of the S3 bucket poli...
1
answers
0
votes
188
views
asked 8 months ago