logo

How to use AWS Resource Control Policies

ID: a3d14d4f-3cde-555e-8319-b4cba68c811b

STIX ID: report--a3d14d4f-3cde-555e-8319-b4cba68c811b

Feed Name: Wiz Blog

Date Published: 2024-11-28

Date Updated: 2026-05-01

...
...

This post introduces AWS Resource Control Policies (RCPs) as organization-wide guardrails for AWS resource policies, outlines key use cases like enforcing data perimeters, limiting IAM role assumption to approved accounts, constraining OIDC access (e.g., GitHub Actions) to trusted tenants, and preventing external actions on resources such as S3. It contrasts RCPs with SCPs, highlights current service coverage and tooling (e.g., Access Analyzer), and provides guidance for safe, staged deployment and monitoring, noting operational caveats such as generic AccessDenied errors and risks if RCPs are removed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.