112. What is a Service Control Policy (SCP)?
In this episode, we provide a friendly introduction to Service Control Policies (SCPs) in AWS Organizations. We explain what SCPs are, how they work, common use cases, and tips for troubleshooting access-denied errors related to SCPs. We cover how SCPs differ from identity-based and resource-based policies, and how SCPs can be used to set boundaries on maximum permissions in AWS accounts across an organization. 💰 SPONSORS 💰 AWS Bites is sponsored by fourTheorem, an AWS Partner with plenty of experience setting up AWS accounts and Service Control Policies. If that's something you'd like some help with, reach out to us on social media or check out https://fourTheorem.com 🔖 Chapters: 00:00 Introduction to service control policies 01:04 Different types of policies in AWS 02:14 Overview of AWS Organizations 07:12 How SCPs work and their key characteristics 12:14 Common use cases for SCPs 16:30 Creating SCPs with infrastructure as code 17:34 Tips for troubleshooting access denied errors from SCPs 18:26 Closing In this episode, we mentioned the following resources: Episode 96: "AWS Governance and Landing Zone with Control Tower, Org Formation, and Terraform": https://awsbites.com/96-aws-governanc... Episode 40: "What do you need to know about IAM?": https://awsbites.com/40-what-do-you-n... Conor Maher's repo with some SCP examples: https://github.com/conzy/terraform-demo You can listen to AWS Bites wherever you get your podcasts: Apple Podcasts: https://podcasts.apple.com/us/podcast... Spotify: https://open.spotify.com/show/3Lh7Pzq... Google: https://podcasts.google.com/feed/aHR0... Breaker: https://www.breaker.audio/aws-bites RSS: https://anchor.fm/s/6a3312a0/podcast/rss Do you have any AWS questions you would like us to address? Leave a comment here or connect with us on X, formerly Twitter: / eoins / loige #aws #scp #policy #accounts #organization #security #bestpractice #governance

114. What's up with LLRT, AWS' new Lambda Runtime?

AWS IAM Core Concepts You NEED to Know

Why Smart People Lose At Office Politics

AWS Organization SCP - Service Control Policy | Concepts | Demo | @Cloud4DevOps

How AI Is Finally Solving Vulnerability Management with Dominik Richter, Mondoo

Something is jamming GPS over Europe. Here's what we found

Create AWS Service Control Policy (AWS SCP)

John Todd Explains Why DNS Matters (Quad9 Interview)

AWS re:Invent 2022 - Best practices for organizing and operating on AWS (COP305)

150. Exploring All-New ECS Managed Instances (MI) Mode

Intro to IAM Roles and Policies on AWS

AWS Security and Compliance Explained | AWS Tutorial | KodeKloud

Amazon Cognito Beginner Guide

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

152. Exploring Lambda Durable Functions

Introduction to AWS Service Control Policies SCPs

Samsung's 990 Pro SSD warranty policy is a scam; I'm taking them to court.

AWS re:Invent 2024 - Understanding security & privacy on Amazon Bedrock, featuring Remitly (AIM360)

Learn IAM (Identity and Access Management) in AWS

