How can the company prevent developer accounts from launching unapproved EC2 instance types?

2 Comments

  1. Albert
    Author

    I systematize that the answer is:
    Create an SCP to deny the ec2:RunInstances API call for instance types that are not in an approved list. Attach the policy to the Developer OU.

  2. Joan
    Author

    I have a feeling that the answer is:
    Create an SCP to deny the ec2:RunInstances API call for instance types that are not in an approved list. Attach the policy to the Developer OU.

Leave a Reply to Joan Cancel reply

Your email address will not be published. Required fields are marked *

thirteen + four =