What is the MOST operationally efficient way to enforce this requirement?

1 Comment

  1. Pamela
    Author

    I compute that the answer is:
    Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.

Leave a Reply

Your email address will not be published. Required fields are marked *

12 + 10 =