All Content tagged with Service Control Policy
Service control policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization.
Content language: English
Filter content
Select tags to filter
Sort by
Sort by most recent
95 results
Chandresh PatelEXPERT
published 21 days ago0 votes93 views
This article explains how to bulk rename AWS resource tag keys using the AWS Resource Groups Tagging API. Since AWS does not support renaming tag keys directly, the approach involves exporting existin...
Rob_HEXPERT
published a month ago0 votes463 views
When enforcing zero data retention on Amazon Bedrock with an SCP, there's an important prerequisite: new accounts default to inherit (not none). The SCP prevents changing the mode, but it doesn't set ...
Darius MousazadehEXPERT
published 2 months ago1 votes215 views
If your organization uses a blanket AI services opt-out policy, opting a single account back in isn't straightforward. The org-wide policy silently blocks child overrides. This article walks through u...
Rahul ASUPPORT ENGINEER
published 3 months ago0 votes255 views
This article provides two Service Control Policies (SCPs) that enforce tagged application inference profiles as the only permitted Bedrock invocation path, enabling organizations to achieve complete g...

We have been hacked and a bad actor has taken over our AWS account. The have instituted a SCP and now we cann...
2
answers
0
votes
87
views
asked 4 months ago
Elvis_PEXPERT
published 4 months ago1 votes351 views
Building an Enterprise Landing Zone
I received a security notice from AWS regarding unauthorized activity on my account. The notice asks me to follow certain remediation steps including checking CloudTrail, rotating access keys, and res...
2
answers
-1
votes
100
views
asked 4 months ago
I am trying to send an outbound WhatsApp message using the StartOutboundChatContact API in Amazon Connect.
API Endpoint:
POST https://connect.us-east-1.amazonaws.com/contact/outbound-chat
Region:
us...
3
answers
0
votes
81
views
asked 5 months ago
I have delegated management of AWS Organizations and Identity Center to a DedicatedAdmin AWS account.
I have setup an identity center group for the Management account. Lets call this group "Mgmt Admi...
2
answers
0
votes
167
views
asked 8 months ago
Ramu VaranasiEXPERT
published 8 months ago0 votes1.2K views
When using Amazon Bedrock with inference profiles in an AWS environment restricted by Control Tower, you may encounter challenges accessing required regions. This article explains how to maintain secu...
Kanwar BajwaEXPERT
published 8 months ago0 votes745 views
Ever worried about accidentally launching expensive AWS resources that blow your budget? This guide shows you how to automatically **prevent new AWS operations** when your spending reaches certain thr...
I tried following the steps: herehttps://repost.aws/questions/QUx25XcQFaQNic0VkqCu3bBw/how-can-i-properly-modify-a-bucket-managed-by-control-tower
However, after creating this role to assume and assi...
5
answers
0
votes
189
views
asked 9 months ago