112. What is a Service Control Policy (SCP)?

Published: 01 February 2024
on channel: AWS Bites
609
19

In this episode, we provide a friendly introduction to Service Control Policies (SCPs) in AWS Organizations. We explain what SCPs are, how they work, common use cases, and tips for troubleshooting access-denied errors related to SCPs. We cover how SCPs differ from identity-based and resource-based policies, and how SCPs can be used to set boundaries on maximum permissions in AWS accounts across an organization.

💰 SPONSORS 💰

AWS Bites is sponsored by fourTheorem, an AWS Partner with plenty of experience setting up AWS accounts and Service Control Policies. If that's something you'd like some help with, reach out to us on social media or check out https://fourTheorem.com


🔖 Chapters:

00:00 Introduction to service control policies
01:04 Different types of policies in AWS
02:14 Overview of AWS Organizations
07:12 How SCPs work and their key characteristics
12:14 Common use cases for SCPs
16:30 Creating SCPs with infrastructure as code
17:34 Tips for troubleshooting access denied errors from SCPs
18:26 Closing



In this episode, we mentioned the following resources:

Episode 96: "AWS Governance and Landing Zone with Control Tower, Org Formation, and Terraform": https://awsbites.com/96-aws-governanc...
Episode 40: "What do you need to know about IAM?": https://awsbites.com/40-what-do-you-n...
Conor Maher's repo with some SCP examples: https://github.com/conzy/terraform-demo


You can listen to AWS Bites wherever you get your podcasts:
Apple Podcasts: https://podcasts.apple.com/us/podcast...
Spotify: https://open.spotify.com/show/3Lh7Pzq...
Google: https://podcasts.google.com/feed/aHR0...
Breaker: https://www.breaker.audio/aws-bites
RSS: ​​https://anchor.fm/s/6a3312a0/podcast/rss

Do you have any AWS questions you would like us to address?
Leave a comment here or connect with us on X, formerly Twitter:
  / eoins  
  / loige  

#aws #scp #policy #accounts #organization #security #bestpractice #governance


Watch video 112. What is a Service Control Policy (SCP)? online without registration, duration hours minute second in high quality. This video was added by user AWS Bites 01 February 2024, don't forget to share it with your friends and acquaintances, it has been viewed on our site 60 once and liked it 1 people.