Updating organization policies with AWS Organizations
When your policy requirements change, you can update an existing policy.
This topic describes how to update policies with AWS Organizations. A policy defines the controls that you want to apply to a group of AWS accounts.
Topics
Update a service control policy (SCP)
When you sign in to your organization's management account, you can rename or change the contents of a policy. Changing the contents of an SCP immediately affects any users, groups, and roles in all attached accounts.
Minimum permissions
To update an SCP, you need permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*")
Update a resource control policy (RCP)
When you sign in to your organization's management account, you can rename or change the contents of a policy. Changing the contents of an RCP immediately affects any resources in all attached accounts.
Minimum permissions
To update an RCP, you need permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*")
Updating a declarative policy
Minimum permissions
To update a declarative policy, you must have permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the Amazon Resource Name (ARN) of the specified policy (or "*")
Update a backup policy
When you sign in to your organization's management account, you can edit a policy that requires changes in your organization.
Minimum permissions
To update a backup policy, you must have permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the policy to update (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the ARN of the policy to update (or "*")
Update a tag policy
Minimum permissions
To update a tag policy, you must have permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*")
Update a chatbot policy
Minimum permissions
To update a chatbot policy, you must have permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*")
Update an AI services opt-out policy
Minimum permissions
To update an AI services opt-out policy, you must have permission to run the following actions:
-
organizations:UpdatePolicy
with aResource
element in the same policy statement that includes the ARN of the specified policy (or "*") -
organizations:DescribePolicy
with aResource
element in the same policy statement that includes the Amazon Resource Name (ARN) of the specified policy (or "*")