What is the MOST operationally efficient way to enforce this requirement?

2 Comments

  1. Pamela
    Author

    I compute that the answer is:
    Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.

  2. Terry
    Author

    I would say the answer is:
    Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.

Leave a Reply

Your email address will not be published. Required fields are marked *

18 + 8 =