How can the company prevent developer accounts from launching unapproved EC2 instance types?

1 Comment

  1. Albert
    Author

    I systematize that the answer is:
    Create an SCP to deny the ec2:RunInstances API call for instance types that are not in an approved list. Attach the policy to the Developer OU.

Leave a Reply

Your email address will not be published. Required fields are marked *

1 × 3 =