CanEnterOrganization

Source reaches org-level control (management account, org policy admin).

cross_boundary CONTROL nature: derived walkable weight 1 high value
Identity  ── CanEnterOrganization ──▸  Organization

Source types

Identity

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

naturederived

Rules that emit CanEnterOrganization 4

cloudformation:CreateStackSet/UpdateStackSet with SERVICE_MANAGED permission model (Organizations integration) deploys to all Org member accounts - equivalent to organization-wide foothold.
awsderived
A DWD SA with both admin-directory and cloud-platform scopes can act as a super-admin and thereby obtain GCP Organization-level control.
gcpderived
Control of a parent administrative boundary inherits transitively to every descendant boundary and resource via Contains*.
derived
Materialize a foothold identity inside a subscription/project/tenant/organization when a principal can impersonate/assume/federate into an identity homed there; escalate to Controls only when entry implies admin at a top boundary.
derived
move · open · esc close