What is the MOST operationally efficient solution that meets these requirements?

1 Comment

  1. Nathan
    Author

    I figure that the answer is:
    Create a service control policy (SCP) in AWS Organizations to deny the ec2:RunInstances action in all unauthorized Regions. Attach this policy to the root level of the organization.

Leave a Reply

Your email address will not be published. Required fields are marked *

15 − nine =