View a markdown version of this page

Policy gestite per la tua organizzazione - AWS Gestione dell'account

Le traduzioni sono generate tramite traduzione automatica. In caso di conflitto tra il contenuto di una traduzione e la versione originale in Inglese, quest'ultima prevarrà.

Policy gestite per la tua organizzazione

avvertimento

Al momento stiamo rilasciando la nostra nuova esperienza a un numero limitato di clienti. Potresti non essere ancora in grado di accedere a questa esperienza.

Quando utilizzi la nostra nuova AWS esperienza, AWS gestisce le politiche di gestione dell'organizzazione, comprese le politiche di controllo delle risorse (RCP) e le politiche di controllo dei servizi (SCP). Questi controlli di protezione impediscono al proprietario del progetto o al membro del team di eseguire azioni che potrebbero inibire le impostazioni preconfigurate preconfigurate definite AWS per aiutarvi a creare e sviluppare rapidamente.

Politiche di controllo dei servizi per i progetti

Quanto segue è una politica di controllo del servizio per tutti gli utenti di un progetto e non può essere modificata:

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "BlockOrgEscape", "Effect" : "Deny", "Action" : [ "account:CloseAccount", "organizations:AcceptHandshake", "organizations:LeaveOrganization", "sso:CreateInstance" ], "Resource" : "*" }, { "Sid" : "ProtectManagedRoles", "Effect" : "Deny", "Action" : [ "iam:AttachRolePolicy", "iam:CreateRole", "iam:DeleteRole", "iam:DeleteRolePermissionsBoundary", "iam:DeleteRolePolicy", "iam:DetachRolePolicy", "iam:PutRolePermissionsBoundary", "iam:PutRolePolicy", "iam:TagRole", "iam:UntagRole", "iam:UpdateAssumeRolePolicy", "iam:UpdateRole" ], "Resource" : "arn:*:iam::*:role/managed/*", "Condition" : { "StringNotLike" : { "aws:PrincipalArn" : "arn:*:iam::*:role/managed/AWSManagedAccountManagementAccessRole" } } } ] }

Questa politica non viene rimossa quando si attivano le funzionalità avanzate. Per ulteriori informazioni, consulta Attiva avanzato AWS caratteristiche.

Inoltre, applichiamo la seguente politica di controllo del servizio per tutti gli utenti di un progetto per limitare alcune modifiche al progetto che non sono supportate o devono essere completate nelle AWS Impostazioni:

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "BlockAccountManagementAPIs", "Effect" : "Deny", "Action" : [ "account:AcceptPrimaryEmailUpdate", "account:DeleteAlternateContact", "account:DisableRegion", "account:EnableRegion", "account:GetAlternateContact", "account:GetContactInformation", "account:GetGovCloudAccountInformation", "account:GetRegionOptStatus", "account:PutAccountName", "account:PutAlternateContact", "account:PutContactInformation", "account:StartPrimaryEmailUpdate" ], "Resource" : "*" }, { "Sid" : "DenyBillingOperations", "Effect" : "Deny", "Action" : "billing:*", "Resource" : "*" }, { "Sid" : "DenyNotificationContactsOperations", "Effect" : "Deny", "Action" : "notifications-contacts:*", "Resource" : "*" }, { "Sid" : "DenyRestrictedNotificationOperations", "Effect" : "Deny", "Action" : [ "notifications:AssociateChannel", "notifications:AssociateManagedNotificationAccountContact", "notifications:AssociateManagedNotificationAdditionalChannel", "notifications:AssociateOrganizationalUnit", "notifications:CreateEventRule", "notifications:CreateNotificationConfiguration", "notifications:DeleteEventRule", "notifications:DeleteNotificationConfiguration", "notifications:DeregisterNotificationHub", "notifications:DisableNotificationsAccessForOrganization", "notifications:DisassociateChannel", "notifications:DisassociateManagedNotificationAccountContact", "notifications:DisassociateManagedNotificationAdditionalChannel", "notifications:DisassociateOrganizationalUnit", "notifications:EnableNotificationsAccessForOrganization", "notifications:GetEventRule", "notifications:GetFeatureOptInStatus", "notifications:GetNotificationConfiguration", "notifications:GetNotificationEvent", "notifications:GetNotificationsAccessForOrganization", "notifications:ListChannels", "notifications:ListEventRules", "notifications:ListManagedNotificationChannelAssociations", "notifications:ListMemberAccounts", "notifications:ListNotificationConfigurations", "notifications:ListNotificationEvents", "notifications:ListNotificationHubs", "notifications:ListOrganizationalUnits", "notifications:ListTagsForResource", "notifications:PutFeatureOptInStatus", "notifications:RegisterNotificationHub", "notifications:TagResource", "notifications:UntagResource", "notifications:UpdateEventRule", "notifications:UpdateNotificationConfiguration" ], "Resource" : "*" }, { "Sid" : "DenyRoleManagerDisablement", "Effect" : "Deny", "Action" : "iam:PutAccountProperties", "Resource" : "*", "Condition" : { "ForAnyValue:StringEquals" : { "iam:AccountPropertyNamespaces" : "RoleManager" } } } ] }

Questa politica viene rimossa quando si attivano le funzionalità avanzate. Per ulteriori informazioni, consulta Attiva avanzato AWS caratteristiche.

Inoltre, applichiamo la seguente politica di controllo dei servizi per tutti gli utenti di un progetto, limitandola Regioni AWS al supporto per i servizi partizionali, a seconda delle esigenze: selected-region

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "UsEast1Partitional", "Effect" : "Deny", "NotAction" : [ "account:*", "acm:AddTagsToCertificate", "acm:DeleteCertificate", "acm:DescribeCertificate", "acm:GetCertificate", "acm:ListCertificates", "acm:ListTagsForCertificate", "acm:RemoveTagsFromCertificate", "acm:RequestCertificate", "acm:ResendValidationEmail", "activate:*", "appfabric:*", "artifact:*", "aws-marketplace:*", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "budgets:*", "ce:*", "chatbot:*", "cloudfront-keyvaluestore:*", "cloudfront:*", "cloudshell:*", "cloudtrail:LookupEvents", "consoleapp:*", "cost-optimization-hub:*", "ec2:DescribeRegions", "ecr-public:*", "freetier:*", "health:*", "iam:*", "identitystore-auth:*", "identitystore:*", "invoicing:*", "kms:CreateGrant", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "machinelearning:*", "managedblockchain-query:*", "managedblockchain:*", "mapcredits:*", "notifications:GetManagedNotificationConfiguration", "notifications:GetManagedNotificationEvent", "notifications:ListManagedNotificationChildEvents", "notifications:ListManagedNotificationConfigurations", "notifications:ListManagedNotificationEvents", "organizations:*", "q:*", "route53:*", "route53domains:*", "route53globalresolver:*", "s3:GetBucketLocation", "s3:ListAllMyBuckets", "signin:*", "sso-directory:*", "sso-oauth:*", "sso:*", "sts:*", "support:*", "tax:*", "trustedadvisor:*", "uxc:*", "waf:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "DenyUsEast1AcmPrivateCaRequests", "Effect" : "Deny", "Action" : "acm:RequestCertificate", "Resource" : "*", "Condition" : { "Null" : { "acm:CertificateAuthority" : "false" }, "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "UsWest2Partitional", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "cloudshell:*", "cloudtrail:LookupEvents", "health:*", "identitystore-auth:*", "identitystore:*", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "networkmanager-chat:*", "networkmanager:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "sso-directory:*", "sso-oauth:*", "sso:*", "support:*", "trustedadvisor:*", "uxc:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-west-2" } } }, { "Sid" : "RegionFloor", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles" ], "Resource" : "*", "Condition" : { "StringNotEquals" : { "aws:RequestedRegion" : [ "unspecified", "us-east-1", "selected-region", "us-west-2" ] } } } ] }

Dopo aver attivato le funzionalità avanzate, al tuo account viene applicata la seguente politica di controllo del servizio:

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "UsEast1Partitional", "Effect" : "Deny", "NotAction" : [ "a4b:*", "access-analyzer:*", "account-access:*", "account:*", "acm:*", "activate:*", "appfabric:*", "artifact:*", "aws-marketplace-management:*", "aws-marketplace:*", "aws-portal:*", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "billing:*", "billingconductor:*", "budgets:*", "builderid:*", "ce:*", "chatbot:*", "chime:*", "cloudfront-keyvaluestore:*", "cloudfront:*", "cloudshell:*", "cloudtrail:LookupEvents", "compute-optimizer:*", "config:*", "consoleapp:*", "consolidatedbilling:*", "cost-optimization-hub:*", "cur:*", "datapipeline:GetAccountLimits", "devicefarm:*", "directconnect:*", "ec2:DescribeRegions", "ec2:DescribeTransitGateways", "ec2:DescribeVpnGateways", "ecr-public:*", "fms:*", "freetier:*", "globalaccelerator:*", "health:*", "iam:*", "identitystore-auth:*", "identitystore:*", "importexport:*", "invoicing:*", "iq:*", "kms:*", "license-manager:ListReceivedLicenses", "lightsail:Get*", "machinelearning:*", "managedblockchain-query:*", "managedblockchain:*", "mapcredits:*", "mobileanalytics:*", "networkmanager:*", "notifications-contacts:*", "notifications:*", "organizations:*", "payments:*", "pricing:*", "q:*", "quicksight:DescribeAccountSubscription", "resource-explorer-2:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "route53:*", "route53domains:*", "route53globalresolver:*", "s3:CreateMultiRegionAccessPoint", "s3:DeleteMultiRegionAccessPoint", "s3:DescribeMultiRegionAccessPointOperation", "s3:GetAccountPublicAccessBlock", "s3:GetBucketLocation", "s3:GetBucketPolicyStatus", "s3:GetBucketPublicAccessBlock", "s3:GetMultiRegionAccessPoint", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "s3:GetStorageLensConfiguration", "s3:GetStorageLensDashboard", "s3:ListAllMyBuckets", "s3:ListMultiRegionAccessPoints", "s3:ListStorageLensConfigurations", "s3:PutAccountPublicAccessBlock", "s3:PutMultiRegionAccessPointPolicy", "savingsplans:*", "shield:*", "signin:*", "sso-directory:*", "sso-oauth:*", "sso:*", "sts:*", "support:*", "supportapp:*", "supportplans:*", "sustainability:*", "tag:GetResources", "tax:*", "trustedadvisor:*", "uxc:*", "vendor-insights:ListEntitledSecurityProfiles", "waf-regional:*", "waf:*", "wafv2:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "UsWest2Partitional", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "cloudshell:*", "cloudtrail:LookupEvents", "health:*", "identitystore-auth:*", "identitystore:*", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "networkmanager-chat:*", "networkmanager:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "sso-directory:*", "sso-oauth:*", "sso:*", "support:*", "trustedadvisor:*", "uxc:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-west-2" } } }, { "Sid" : "RegionFloor", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles" ], "Resource" : "*", "Condition" : { "StringNotEquals" : { "aws:RequestedRegion" : [ "unspecified", "us-east-1", "selected-region", "us-west-2" ] } } } ] }

Politiche di controllo del servizio per i limiti di spesa

Se si utilizza un limite di spesa, le seguenti politiche di controllo del servizio vengono applicate al progetto man mano che si avvicina al limite di spesa. Per ulteriori informazioni sui limiti di spesa, consultaCrea un limite di spesa in AWS Settings.

{ "Version": "2012-10-17", "Statement": { "Sid": "DenyBedrockUsage", "Effect": "Deny", "Action": [ "bedrock:ApplyGuardrail", "bedrock:CallWithBearerToken", "bedrock:InvokeAgent", "bedrock:InvokeAutomatedReasoningPolicy", "bedrock:InvokeDataAutomation", "bedrock:InvokeDataAutomationAsync", "bedrock:InvokeFlow", "bedrock:InvokeInlineAgent", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:InvokeTool", "bedrock:OptimizePrompt", "bedrock:Retrieve", "bedrock:RetrieveAndGenerate", "bedrock:StartFlowExecution", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": { "Sid": "DenyLambdaUsage", "Effect": "Deny", "Action": [ "lambda:DeleteFunctionConcurrency", "lambda:InvokeAsync", "lambda:InvokeFunction", "lambda:InvokeFunctionUrl", "lambda:PutFunctionConcurrency" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": { "Sid": "DenySageMakerInference", "Effect": "Deny", "Action": [ "sagemaker:InvokeEndpoint", "sagemaker:InvokeEndpointAsync", "sagemaker:InvokeEndpointWithResponseStream" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyCompute", "Effect": "Deny", "Action": [ "ec2:CreateNatGateway", "ec2:CreateVolume", "ec2:CreateVpnConnection", "ec2:RunInstances", "ec2:StartInstances", "elasticloadbalancing:CreateLoadBalancer", "autoscaling:CreateAutoScalingGroup", "ecs:CreateService", "eks:CreateCluster", "eks:CreateNodegroup", "eks:CreateFargateProfile", "elasticbeanstalk:CreateEnvironment", "apprunner:CreateService", "apprunner:ResumeService", "batch:CreateComputeEnvironment", "elasticmapreduce:RunJobFlow", "appstream:CreateFleet" ], "Resource": "*" }, { "Sid": "DenyLambda", "Effect": "Deny", "Action": "lambda:CreateFunction", "Resource": "*" }, { "Sid": "DenyDatabase", "Effect": "Deny", "Action": [ "rds:CreateDBCluster", "rds:CreateDBInstance", "rds:RestoreDBClusterFromS3", "rds:RestoreDBClusterFromSnapshot", "rds:RestoreDBClusterToPointInTime", "rds:RestoreDBInstanceFromDBSnapshot", "rds:RestoreDBInstanceFromS3", "rds:RestoreDBInstanceToPointInTime", "rds:StartDBCluster", "rds:StartDBInstance", "dynamodb:CreateTable", "dynamodb:CreateGlobalTable", "elasticache:CreateCacheCluster", "elasticache:CreateReplicationGroup", "timestream:CreateDatabase", "timestream:CreateTable", "memorydb:CreateCluster", "es:CreateDomain", "aoss:CreateCollection", "redshift:CreateCluster", "redshift:ResumeCluster", "redshift-serverless:CreateWorkgroup", "dsql:CreateCluster" ], "Resource": "*" }, { "Sid": "DenyStorage", "Effect": "Deny", "Action": [ "elasticfilesystem:CreateFileSystem", "datasync:CreateTask", "storagegateway:ActivateGateway", "glacier:CreateVault" ], "Resource": "*" }, { "Sid": "DenySageMaker", "Effect": "Deny", "Action": [ "sagemaker:CreateApp", "sagemaker:CreateEndpoint", "sagemaker:CreateNotebookInstance", "sagemaker:CreateProcessingJob", "sagemaker:CreateTrainingJob", "sagemaker:CreateTransformJob", "sagemaker:StartNotebookInstance" ], "Resource": "*" }, { "Sid": "DenyBedrock", "Effect": "Deny", "Action": [ "bedrock:CreateCustomModelDeployment", "bedrock:CreateDataAutomationProject", "bedrock:CreateEvaluationJob", "bedrock:CreateMarketplaceModelEndpoint", "bedrock:CreateModelCustomizationJob", "bedrock:CreateModelImportJob", "bedrock:CreateModelInvocationJob", "bedrock:CreateProvisionedModelThroughput", "bedrock-mantle:CreateCustomizedModel", "bedrock-mantle:CreateFineTuningJob", "bedrock-mantle:CreateReservation" ], "Resource": "*" }, { "Sid": "DenyAIML", "Effect": "Deny", "Action": [ "kendra:CreateIndex", "personalize:CreateSolution", "personalize:CreateCampaign", "forecast:CreatePredictor", "forecast:CreateForecast", "rekognition:CreateProject", "lex:CreateBot" ], "Resource": "*" }, { "Sid": "DenyNetworking", "Effect": "Deny", "Action": [ "cloudfront:CreateDistribution", "route53:CreateHostedZone", "appmesh:CreateMesh" ], "Resource": "*" }, { "Sid": "DenyApiGatewayCreate", "Effect": "Deny", "Action": "apigateway:POST", "Resource": [ "arn:aws:apigateway:*::/restapis", "arn:aws:apigateway:*::/apis" ] }, { "Sid": "DenyMessaging", "Effect": "Deny", "Action": [ "mq:CreateBroker", "kafka:CreateCluster", "kafka:CreateVpcConnection", "kinesis:CreateStream", "firehose:CreateDeliveryStream", "kinesisanalytics:CreateApplication", "kinesisvideo:CreateStream", "sns:CreateTopic", "sqs:CreateQueue", "events:CreateEventBus", "pipes:CreatePipe", "scheduler:CreateSchedule" ], "Resource": "*" }, { "Sid": "DenyAnalytics", "Effect": "Deny", "Action": [ "states:CreateStateMachine", "glue:CreateJob", "glue:CreateCrawler", "athena:CreateWorkGroup", "appsync:CreateGraphqlApi", "appflow:CreateFlow", "datazone:CreateDomain", "datazone:CreateProject", "entityresolution:CreateMatchingWorkflow", "datapipeline:CreatePipeline", "dataexchange:CreateDataSet" ], "Resource": "*" }, { "Sid": "DenyDevTools", "Effect": "Deny", "Action": [ "amplify:CreateApp", "amplify:CreateBranch", "cloud9:CreateEnvironmentEC2", "codebuild:CreateProject", "codepipeline:CreatePipeline", "codedeploy:CreateApplication", "cloudformation:CreateStack", "cloudformation:CreateStackSet", "codeartifact:CreateRepository", "codeartifact:CreateDomain" ], "Resource": "*" }, { "Sid": "DenySecurity", "Effect": "Deny", "Action": [ "kms:CreateKey", "wafv2:CreateWebACL", "cloudhsm:CreateCluster", "network-firewall:CreateFirewall", "secretsmanager:CreateSecret", "acm-pca:CreateCertificateAuthority", "cognito-idp:CreateUserPool", "cognito-identity:CreateIdentityPool", "ds:CreateDirectory", "ds:CreateMicrosoftAD", "fms:PutPolicy", "payment-cryptography:CreateKey" ], "Resource": "*" }, { "Sid": "DenyMedia", "Effect": "Deny", "Action": [ "medialive:CreateChannel", "mediapackage:CreateChannel", "mediaconnect:CreateFlow", "mediatailor:CreateChannel" ], "Resource": "*" }, { "Sid": "DenyIoT", "Effect": "Deny", "Action": [ "iot:CreateThing", "iot:CreateTopicRule", "iotevents:CreateDetectorModel", "iottwinmaker:CreateWorkspace", "iotsitewise:CreateAssetModel", "iotsitewise:CreatePortal", "iotfleetwise:CreateCampaign" ], "Resource": "*" }, { "Sid": "DenyMisc", "Effect": "Deny", "Action": [ "ses:CreateConfigurationSet", "ecr:CreateRepository", "aps:CreateWorkspace", "healthlake:CreateFHIRDatastore", "transfer:CreateServer", "managedblockchain:CreateNetwork", "managedblockchain:CreateMember", "route53-recovery-control-config:CreateCluster", "fis:CreateExperimentTemplate", "appfabric:CreateAppBundle", "appfabric:CreateIngestion", "b2bi:CreateProfile", "b2bi:CreateTransformer", "geo:CreateMap", "geo:CreatePlaceIndex", "geo:CreateTracker", "geo:CreateGeofenceCollection", "geo:CreateRouteCalculator" ], "Resource": "*" } ] }

Politiche di controllo delle risorse per i progetti

Di seguito è riportata la politica di controllo delle risorse per le risorse del progetto. Questa politica non può essere modificata:

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "DenyAnyoneOutsideMyOrgAndAWS", "Effect" : "Deny", "Principal" : "*", "Action" : [ "aoss:*", "appconfig:*", "appstream:*", "autoscaling:*", "codebuild:*", "codecommit:*", "cognito-identity:*", "cognito-idp:*", "comprehend:*", "comprehendmedical:*", "dax:*", "dynamodb:*", "ecr:*", "health:*", "kinesisvideo:*", "kms:*", "logs:*", "s3:*", "secretsmanager:*", "sqs:*", "sts:*", "support:*", "textract:*", "transcribe:*", "translate:*" ], "Resource" : "*", "Condition" : { "BoolIfExists" : { "aws:PrincipalIsAWSService" : "false" }, "Null" : { "aws:PrincipalARN" : "false" }, "StringNotEqualsIfExists" : { "aws:PrincipalOrgID" : "${aws:ResourceOrgID}" } } }, { "Sid" : "DenyAWSWhenItsNotMyOrgsSourceAccount", "Effect" : "Deny", "Principal" : "*", "Action" : [ "aoss:*", "appconfig:*", "appstream:*", "autoscaling:*", "codebuild:*", "codecommit:*", "cognito-identity:*", "cognito-idp:*", "comprehend:*", "comprehendmedical:*", "dax:*", "dynamodb:*", "ecr:*", "health:*", "kinesisvideo:*", "kms:*", "logs:*", "s3:*", "secretsmanager:*", "sqs:*", "sts:*", "support:*", "textract:*", "transcribe:*", "translate:*" ], "Resource" : "*", "Condition" : { "Null" : { "aws:SourceAccount" : "false" }, "StringNotEquals" : { "aws:SourceOrgID" : "${aws:ResourceOrgID}" } } } ] }