Skip to content

Topic

Cloud access control

How cloud platforms decide whether a principal may perform an action, covering identity policies, resource policies, organization-level guardrails and the order in which they are evaluated.

Current clusters

build1 publisher

One allow-list SCP on an OU caps what every account below it can do

AWS Organizations permits an action only when SCPs allow it at every node from root to account, up to seven deep, a dev.to production guide explains. Its most common incident is one OU losing FullAWSAccess, so an AccessDenied has to be traced through the SCPs on every node in the path.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence60