What is the MOST operationally efficient way to enforce this requirement?

2 Comments

  1. James
    Author

    From my perspective, the answer is:
    Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.

  2. Frances
    Author

    It seems to me that the answer is:
    Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.

Leave a Reply to Frances Cancel reply

Your email address will not be published. Required fields are marked *

fifteen − six =