What is the MOST operationally efficient way to enforce this requirement?

1 Comment

  1. James
    Author

    From my perspective, the answer is:
    Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.

Leave a Reply

Your email address will not be published. Required fields are marked *

3 × 3 =