Which solution will meet these requirements with minimal optional overhead?

1 Comment

  1. Adam
    Author

    I opine that the answer is:
    Use an SCP in Organizations to implement an allow list of AWS services. Apply this SCP at the root level. Remove the default AWS managed SCP from the root level and all OU levels. For any specific exceptions for an OU, modify the SCP attached to that OU, and add the required AWS services to the allow list.

Leave a Reply

Your email address will not be published. Required fields are marked *

5 + 17 =