Les traductions sont fournies par des outils de traduction automatique. En cas de conflit entre le contenu d'une traduction et celui de la version originale en anglais, la version anglaise prévaudra.
Politiques gérées pour votre organisation
Avertissement
Nous proposons actuellement notre nouvelle expérience à un nombre limité de clients. Il se peut que vous ne puissiez pas encore accéder à cette expérience.
Lorsque vous utilisez notre nouvelle AWS expérience, elle AWS gère les politiques de gestion de l'organisation, y compris les politiques de contrôle des ressources (RCP) et les politiques de contrôle des services (SCP). Ces contrôles de protection empêchent le propriétaire du projet ou un membre de l'équipe d'effectuer des actions qui empêcheraient les paramètres par défaut AWS préconfigurés définis pour vous aider à créer et à développer rapidement.
Politiques de contrôle des services pour les projets
La politique de contrôle des services suivante s'applique à tous les utilisateurs d'un projet et ne peut pas être modifiée :
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "BlockOrgEscape", "Effect" : "Deny", "Action" : [ "account:CloseAccount", "organizations:AcceptHandshake", "organizations:LeaveOrganization", "sso:CreateInstance" ], "Resource" : "*" }, { "Sid" : "ProtectManagedRoles", "Effect" : "Deny", "Action" : [ "iam:AttachRolePolicy", "iam:CreateRole", "iam:DeleteRole", "iam:DeleteRolePermissionsBoundary", "iam:DeleteRolePolicy", "iam:DetachRolePolicy", "iam:PutRolePermissionsBoundary", "iam:PutRolePolicy", "iam:TagRole", "iam:UntagRole", "iam:UpdateAssumeRolePolicy", "iam:UpdateRole" ], "Resource" : "arn:*:iam::*:role/managed/*", "Condition" : { "StringNotLike" : { "aws:PrincipalArn" : "arn:*:iam::*:role/managed/AWSManagedAccountManagementAccessRole" } } } ] }
Cette politique n'est pas supprimée lorsque vous activez les fonctionnalités avancées. Pour de plus amples informations, veuillez consulter Activer la fonctionnalité avancée AWS fonctionnalités.
En outre, nous appliquons la politique de contrôle de service suivante à tous les utilisateurs d'un projet afin de limiter certaines modifications de votre projet qui ne sont pas prises en charge ou doivent être effectuées dans AWS les paramètres :
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "BlockAccountManagementAPIs", "Effect" : "Deny", "Action" : [ "account:AcceptPrimaryEmailUpdate", "account:DeleteAlternateContact", "account:DisableRegion", "account:EnableRegion", "account:GetAlternateContact", "account:GetContactInformation", "account:GetGovCloudAccountInformation", "account:GetRegionOptStatus", "account:PutAccountName", "account:PutAlternateContact", "account:PutContactInformation", "account:StartPrimaryEmailUpdate" ], "Resource" : "*" }, { "Sid" : "DenyBillingOperations", "Effect" : "Deny", "Action" : "billing:*", "Resource" : "*" }, { "Sid" : "DenyNotificationContactsOperations", "Effect" : "Deny", "Action" : "notifications-contacts:*", "Resource" : "*" }, { "Sid" : "DenyRestrictedNotificationOperations", "Effect" : "Deny", "Action" : [ "notifications:AssociateChannel", "notifications:AssociateManagedNotificationAccountContact", "notifications:AssociateManagedNotificationAdditionalChannel", "notifications:AssociateOrganizationalUnit", "notifications:CreateEventRule", "notifications:CreateNotificationConfiguration", "notifications:DeleteEventRule", "notifications:DeleteNotificationConfiguration", "notifications:DeregisterNotificationHub", "notifications:DisableNotificationsAccessForOrganization", "notifications:DisassociateChannel", "notifications:DisassociateManagedNotificationAccountContact", "notifications:DisassociateManagedNotificationAdditionalChannel", "notifications:DisassociateOrganizationalUnit", "notifications:EnableNotificationsAccessForOrganization", "notifications:GetEventRule", "notifications:GetFeatureOptInStatus", "notifications:GetNotificationConfiguration", "notifications:GetNotificationEvent", "notifications:GetNotificationsAccessForOrganization", "notifications:ListChannels", "notifications:ListEventRules", "notifications:ListManagedNotificationChannelAssociations", "notifications:ListMemberAccounts", "notifications:ListNotificationConfigurations", "notifications:ListNotificationEvents", "notifications:ListNotificationHubs", "notifications:ListOrganizationalUnits", "notifications:ListTagsForResource", "notifications:PutFeatureOptInStatus", "notifications:RegisterNotificationHub", "notifications:TagResource", "notifications:UntagResource", "notifications:UpdateEventRule", "notifications:UpdateNotificationConfiguration" ], "Resource" : "*" }, { "Sid" : "DenyRoleManagerDisablement", "Effect" : "Deny", "Action" : "iam:PutAccountProperties", "Resource" : "*", "Condition" : { "ForAnyValue:StringEquals" : { "iam:AccountPropertyNamespaces" : "RoleManager" } } } ] }
Cette politique est supprimée lorsque vous activez les fonctionnalités avancées. Pour de plus amples informations, veuillez consulter Activer la fonctionnalité avancée AWS fonctionnalités.
En outre, nous appliquons également la politique de contrôle des services suivante à tous les utilisateurs d'un projet afin de limiter Régions AWS la prise en charge des services partitionnels, en fonction de vos selected-region besoins :
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "UsEast1Partitional", "Effect" : "Deny", "NotAction" : [ "account:*", "acm:AddTagsToCertificate", "acm:DeleteCertificate", "acm:DescribeCertificate", "acm:GetCertificate", "acm:ListCertificates", "acm:ListTagsForCertificate", "acm:RemoveTagsFromCertificate", "acm:RequestCertificate", "acm:ResendValidationEmail", "activate:*", "appfabric:*", "artifact:*", "aws-marketplace:*", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "budgets:*", "ce:*", "chatbot:*", "cloudfront-keyvaluestore:*", "cloudfront:*", "cloudshell:*", "cloudtrail:LookupEvents", "consoleapp:*", "cost-optimization-hub:*", "ec2:DescribeRegions", "ecr-public:*", "freetier:*", "health:*", "iam:*", "identitystore-auth:*", "identitystore:*", "invoicing:*", "kms:CreateGrant", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "machinelearning:*", "managedblockchain-query:*", "managedblockchain:*", "mapcredits:*", "notifications:GetManagedNotificationConfiguration", "notifications:GetManagedNotificationEvent", "notifications:ListManagedNotificationChildEvents", "notifications:ListManagedNotificationConfigurations", "notifications:ListManagedNotificationEvents", "organizations:*", "q:*", "route53:*", "route53domains:*", "route53globalresolver:*", "s3:GetBucketLocation", "s3:ListAllMyBuckets", "signin:*", "sso-directory:*", "sso-oauth:*", "sso:*", "sts:*", "support:*", "tax:*", "trustedadvisor:*", "uxc:*", "waf:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "DenyUsEast1AcmPrivateCaRequests", "Effect" : "Deny", "Action" : "acm:RequestCertificate", "Resource" : "*", "Condition" : { "Null" : { "acm:CertificateAuthority" : "false" }, "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "UsWest2Partitional", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "cloudshell:*", "cloudtrail:LookupEvents", "health:*", "identitystore-auth:*", "identitystore:*", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "networkmanager-chat:*", "networkmanager:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "sso-directory:*", "sso-oauth:*", "sso:*", "support:*", "trustedadvisor:*", "uxc:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-west-2" } } }, { "Sid" : "RegionFloor", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles" ], "Resource" : "*", "Condition" : { "StringNotEquals" : { "aws:RequestedRegion" : [ "unspecified", "us-east-1", "selected-region", "us-west-2" ] } } } ] }
Une fois les fonctionnalités avancées activées, la politique de contrôle des services suivante est appliquée à votre compte :
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "UsEast1Partitional", "Effect" : "Deny", "NotAction" : [ "a4b:*", "access-analyzer:*", "account-access:*", "account:*", "acm:*", "activate:*", "appfabric:*", "artifact:*", "aws-marketplace-management:*", "aws-marketplace:*", "aws-portal:*", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "billing:*", "billingconductor:*", "budgets:*", "builderid:*", "ce:*", "chatbot:*", "chime:*", "cloudfront-keyvaluestore:*", "cloudfront:*", "cloudshell:*", "cloudtrail:LookupEvents", "compute-optimizer:*", "config:*", "consoleapp:*", "consolidatedbilling:*", "cost-optimization-hub:*", "cur:*", "datapipeline:GetAccountLimits", "devicefarm:*", "directconnect:*", "ec2:DescribeRegions", "ec2:DescribeTransitGateways", "ec2:DescribeVpnGateways", "ecr-public:*", "fms:*", "freetier:*", "globalaccelerator:*", "health:*", "iam:*", "identitystore-auth:*", "identitystore:*", "importexport:*", "invoicing:*", "iq:*", "kms:*", "license-manager:ListReceivedLicenses", "lightsail:Get*", "machinelearning:*", "managedblockchain-query:*", "managedblockchain:*", "mapcredits:*", "mobileanalytics:*", "networkmanager:*", "notifications-contacts:*", "notifications:*", "organizations:*", "payments:*", "pricing:*", "q:*", "quicksight:DescribeAccountSubscription", "resource-explorer-2:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "route53:*", "route53domains:*", "route53globalresolver:*", "s3:CreateMultiRegionAccessPoint", "s3:DeleteMultiRegionAccessPoint", "s3:DescribeMultiRegionAccessPointOperation", "s3:GetAccountPublicAccessBlock", "s3:GetBucketLocation", "s3:GetBucketPolicyStatus", "s3:GetBucketPublicAccessBlock", "s3:GetMultiRegionAccessPoint", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "s3:GetStorageLensConfiguration", "s3:GetStorageLensDashboard", "s3:ListAllMyBuckets", "s3:ListMultiRegionAccessPoints", "s3:ListStorageLensConfigurations", "s3:PutAccountPublicAccessBlock", "s3:PutMultiRegionAccessPointPolicy", "savingsplans:*", "shield:*", "signin:*", "sso-directory:*", "sso-oauth:*", "sso:*", "sts:*", "support:*", "supportapp:*", "supportplans:*", "sustainability:*", "tag:GetResources", "tax:*", "trustedadvisor:*", "uxc:*", "vendor-insights:ListEntitledSecurityProfiles", "waf-regional:*", "waf:*", "wafv2:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "UsWest2Partitional", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "cloudshell:*", "cloudtrail:LookupEvents", "health:*", "identitystore-auth:*", "identitystore:*", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "networkmanager-chat:*", "networkmanager:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "sso-directory:*", "sso-oauth:*", "sso:*", "support:*", "trustedadvisor:*", "uxc:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-west-2" } } }, { "Sid" : "RegionFloor", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles" ], "Resource" : "*", "Condition" : { "StringNotEquals" : { "aws:RequestedRegion" : [ "unspecified", "us-east-1", "selected-region", "us-west-2" ] } } } ] }
Politiques de contrôle des services pour les limites de dépenses
Si vous utilisez une limite de dépenses, les politiques de contrôle des services suivantes sont appliquées à votre projet lorsqu'il approche de la limite de dépenses. Pour plus d'informations sur les limites de dépenses, consultezCréez une limite de dépenses dans AWS Settings.
{ "Version": "2012-10-17", "Statement": { "Sid": "DenyBedrockUsage", "Effect": "Deny", "Action": [ "bedrock:ApplyGuardrail", "bedrock:CallWithBearerToken", "bedrock:InvokeAgent", "bedrock:InvokeAutomatedReasoningPolicy", "bedrock:InvokeDataAutomation", "bedrock:InvokeDataAutomationAsync", "bedrock:InvokeFlow", "bedrock:InvokeInlineAgent", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:InvokeTool", "bedrock:OptimizePrompt", "bedrock:Retrieve", "bedrock:RetrieveAndGenerate", "bedrock:StartFlowExecution", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": { "Sid": "DenyLambdaUsage", "Effect": "Deny", "Action": [ "lambda:DeleteFunctionConcurrency", "lambda:InvokeAsync", "lambda:InvokeFunction", "lambda:InvokeFunctionUrl", "lambda:PutFunctionConcurrency" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": { "Sid": "DenySageMakerInference", "Effect": "Deny", "Action": [ "sagemaker:InvokeEndpoint", "sagemaker:InvokeEndpointAsync", "sagemaker:InvokeEndpointWithResponseStream" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyCompute", "Effect": "Deny", "Action": [ "ec2:CreateNatGateway", "ec2:CreateVolume", "ec2:CreateVpnConnection", "ec2:RunInstances", "ec2:StartInstances", "elasticloadbalancing:CreateLoadBalancer", "autoscaling:CreateAutoScalingGroup", "ecs:CreateService", "eks:CreateCluster", "eks:CreateNodegroup", "eks:CreateFargateProfile", "elasticbeanstalk:CreateEnvironment", "apprunner:CreateService", "apprunner:ResumeService", "batch:CreateComputeEnvironment", "elasticmapreduce:RunJobFlow", "appstream:CreateFleet" ], "Resource": "*" }, { "Sid": "DenyLambda", "Effect": "Deny", "Action": "lambda:CreateFunction", "Resource": "*" }, { "Sid": "DenyDatabase", "Effect": "Deny", "Action": [ "rds:CreateDBCluster", "rds:CreateDBInstance", "rds:RestoreDBClusterFromS3", "rds:RestoreDBClusterFromSnapshot", "rds:RestoreDBClusterToPointInTime", "rds:RestoreDBInstanceFromDBSnapshot", "rds:RestoreDBInstanceFromS3", "rds:RestoreDBInstanceToPointInTime", "rds:StartDBCluster", "rds:StartDBInstance", "dynamodb:CreateTable", "dynamodb:CreateGlobalTable", "elasticache:CreateCacheCluster", "elasticache:CreateReplicationGroup", "timestream:CreateDatabase", "timestream:CreateTable", "memorydb:CreateCluster", "es:CreateDomain", "aoss:CreateCollection", "redshift:CreateCluster", "redshift:ResumeCluster", "redshift-serverless:CreateWorkgroup", "dsql:CreateCluster" ], "Resource": "*" }, { "Sid": "DenyStorage", "Effect": "Deny", "Action": [ "elasticfilesystem:CreateFileSystem", "datasync:CreateTask", "storagegateway:ActivateGateway", "glacier:CreateVault" ], "Resource": "*" }, { "Sid": "DenySageMaker", "Effect": "Deny", "Action": [ "sagemaker:CreateApp", "sagemaker:CreateEndpoint", "sagemaker:CreateNotebookInstance", "sagemaker:CreateProcessingJob", "sagemaker:CreateTrainingJob", "sagemaker:CreateTransformJob", "sagemaker:StartNotebookInstance" ], "Resource": "*" }, { "Sid": "DenyBedrock", "Effect": "Deny", "Action": [ "bedrock:CreateCustomModelDeployment", "bedrock:CreateDataAutomationProject", "bedrock:CreateEvaluationJob", "bedrock:CreateMarketplaceModelEndpoint", "bedrock:CreateModelCustomizationJob", "bedrock:CreateModelImportJob", "bedrock:CreateModelInvocationJob", "bedrock:CreateProvisionedModelThroughput", "bedrock-mantle:CreateCustomizedModel", "bedrock-mantle:CreateFineTuningJob", "bedrock-mantle:CreateReservation" ], "Resource": "*" }, { "Sid": "DenyAIML", "Effect": "Deny", "Action": [ "kendra:CreateIndex", "personalize:CreateSolution", "personalize:CreateCampaign", "forecast:CreatePredictor", "forecast:CreateForecast", "rekognition:CreateProject", "lex:CreateBot" ], "Resource": "*" }, { "Sid": "DenyNetworking", "Effect": "Deny", "Action": [ "cloudfront:CreateDistribution", "route53:CreateHostedZone", "appmesh:CreateMesh" ], "Resource": "*" }, { "Sid": "DenyApiGatewayCreate", "Effect": "Deny", "Action": "apigateway:POST", "Resource": [ "arn:aws:apigateway:*::/restapis", "arn:aws:apigateway:*::/apis" ] }, { "Sid": "DenyMessaging", "Effect": "Deny", "Action": [ "mq:CreateBroker", "kafka:CreateCluster", "kafka:CreateVpcConnection", "kinesis:CreateStream", "firehose:CreateDeliveryStream", "kinesisanalytics:CreateApplication", "kinesisvideo:CreateStream", "sns:CreateTopic", "sqs:CreateQueue", "events:CreateEventBus", "pipes:CreatePipe", "scheduler:CreateSchedule" ], "Resource": "*" }, { "Sid": "DenyAnalytics", "Effect": "Deny", "Action": [ "states:CreateStateMachine", "glue:CreateJob", "glue:CreateCrawler", "athena:CreateWorkGroup", "appsync:CreateGraphqlApi", "appflow:CreateFlow", "datazone:CreateDomain", "datazone:CreateProject", "entityresolution:CreateMatchingWorkflow", "datapipeline:CreatePipeline", "dataexchange:CreateDataSet" ], "Resource": "*" }, { "Sid": "DenyDevTools", "Effect": "Deny", "Action": [ "amplify:CreateApp", "amplify:CreateBranch", "cloud9:CreateEnvironmentEC2", "codebuild:CreateProject", "codepipeline:CreatePipeline", "codedeploy:CreateApplication", "cloudformation:CreateStack", "cloudformation:CreateStackSet", "codeartifact:CreateRepository", "codeartifact:CreateDomain" ], "Resource": "*" }, { "Sid": "DenySecurity", "Effect": "Deny", "Action": [ "kms:CreateKey", "wafv2:CreateWebACL", "cloudhsm:CreateCluster", "network-firewall:CreateFirewall", "secretsmanager:CreateSecret", "acm-pca:CreateCertificateAuthority", "cognito-idp:CreateUserPool", "cognito-identity:CreateIdentityPool", "ds:CreateDirectory", "ds:CreateMicrosoftAD", "fms:PutPolicy", "payment-cryptography:CreateKey" ], "Resource": "*" }, { "Sid": "DenyMedia", "Effect": "Deny", "Action": [ "medialive:CreateChannel", "mediapackage:CreateChannel", "mediaconnect:CreateFlow", "mediatailor:CreateChannel" ], "Resource": "*" }, { "Sid": "DenyIoT", "Effect": "Deny", "Action": [ "iot:CreateThing", "iot:CreateTopicRule", "iotevents:CreateDetectorModel", "iottwinmaker:CreateWorkspace", "iotsitewise:CreateAssetModel", "iotsitewise:CreatePortal", "iotfleetwise:CreateCampaign" ], "Resource": "*" }, { "Sid": "DenyMisc", "Effect": "Deny", "Action": [ "ses:CreateConfigurationSet", "ecr:CreateRepository", "aps:CreateWorkspace", "healthlake:CreateFHIRDatastore", "transfer:CreateServer", "managedblockchain:CreateNetwork", "managedblockchain:CreateMember", "route53-recovery-control-config:CreateCluster", "fis:CreateExperimentTemplate", "appfabric:CreateAppBundle", "appfabric:CreateIngestion", "b2bi:CreateProfile", "b2bi:CreateTransformer", "geo:CreateMap", "geo:CreatePlaceIndex", "geo:CreateTracker", "geo:CreateGeofenceCollection", "geo:CreateRouteCalculator" ], "Resource": "*" } ] }
Politiques de contrôle des ressources pour les projets
Voici la politique de contrôle des ressources pour les ressources du projet. Cette politique ne peut pas être modifiée :
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "DenyAnyoneOutsideMyOrgAndAWS", "Effect" : "Deny", "Principal" : "*", "Action" : [ "aoss:*", "appconfig:*", "appstream:*", "autoscaling:*", "codebuild:*", "codecommit:*", "cognito-identity:*", "cognito-idp:*", "comprehend:*", "comprehendmedical:*", "dax:*", "dynamodb:*", "ecr:*", "health:*", "kinesisvideo:*", "kms:*", "logs:*", "s3:*", "secretsmanager:*", "sqs:*", "sts:*", "support:*", "textract:*", "transcribe:*", "translate:*" ], "Resource" : "*", "Condition" : { "BoolIfExists" : { "aws:PrincipalIsAWSService" : "false" }, "Null" : { "aws:PrincipalARN" : "false" }, "StringNotEqualsIfExists" : { "aws:PrincipalOrgID" : "${aws:ResourceOrgID}" } } }, { "Sid" : "DenyAWSWhenItsNotMyOrgsSourceAccount", "Effect" : "Deny", "Principal" : "*", "Action" : [ "aoss:*", "appconfig:*", "appstream:*", "autoscaling:*", "codebuild:*", "codecommit:*", "cognito-identity:*", "cognito-idp:*", "comprehend:*", "comprehendmedical:*", "dax:*", "dynamodb:*", "ecr:*", "health:*", "kinesisvideo:*", "kms:*", "logs:*", "s3:*", "secretsmanager:*", "sqs:*", "sts:*", "support:*", "textract:*", "transcribe:*", "translate:*" ], "Resource" : "*", "Condition" : { "Null" : { "aws:SourceAccount" : "false" }, "StringNotEquals" : { "aws:SourceOrgID" : "${aws:ResourceOrgID}" } } } ] }