Which solution will meet this requirement with the LEAST operational overhead?

1 Comment

  1. Christina
    Author

    My best guess is:
    Configure an SCP to deny the ec2:AuthorizeSecurityGroupIngress action when the value of the aws:SourceIp condition key is 0.0.0.0/0. Apply the SCP to the NonProd OU.

Leave a Reply

Your email address will not be published. Required fields are marked *

three × four =