Which solution will meet this requirement with the LEAST operational overhead?

2 Comments

  1. Christina
    Author

    My best guess is:
    Configure an SCP to deny the ec2:AuthorizeSecurityGroupIngress action when the value of the aws:SourceIp condition key is 0.0.0.0/0. Apply the SCP to the NonProd OU.

  2. Jonathan
    Author

    I draft that the answer is:
    Configure an SCP to deny the ec2:AuthorizeSecurityGroupIngress action when the value of the aws:SourceIp condition key is 0.0.0.0/0. Apply the SCP to the NonProd OU.

Leave a Reply to Jonathan Cancel reply

Your email address will not be published. Required fields are marked *

seven − one =