ServiceControlPolicy

AWS SCP guardrail.

class: Policy derivation-only - no collection recipe

Realizing resources

This type has no collection recipe - it appears only as the endpoint of derived edges.

Exposure sites

None.

Rules that touch ServiceControlPolicy 5

Deregistering an OU from Control Tower governance (or reparenting accounts) removes the inherited SCP guardrails from those accounts.
Disabling or updating a Control Tower preventive control modifies the SCP guardrail backing it, removing its deny.
A principal who can modify or escape a guardrail (SCP / Org Policy / deny assignment) upgrades the edges that guardrail was suppressing from BLOCKED to their underlying state.
?cap
move · open · esc close