ServiceControlPolicy
AWS SCP guardrail.
class: Policy derivation-only - no collection recipe
Realizing resources
This type has no collection recipe - it appears only as the endpoint of derived edges.
As edge source
As edge target
Exposure sites
None.
Rules that touch ServiceControlPolicy 5
Deregistering an OU from Control Tower governance (or reparenting accounts) removes the inherited SCP guardrails from those accounts.
Disabling or updating a Control Tower preventive control modifies the SCP guardrail backing it, removing its deny.
aws
CanModifyPolicyA principal who can modify or escape a guardrail (SCP / Org Policy / deny assignment) upgrades the edges that guardrail was suppressing from BLOCKED to their underlying state.
?cap