AWS Organizations now offers full IAM policy language support for service control policies (SCPs), enabling you to write SCPs with the same flexibility as IAM managed policies. With this launch, SCPs now support use of conditions, individual resource ARNs, and the NotAction element with Allow statements. Additionally, you can now use wildcards at the beginning or middle of Action element strings and the NotResource element.
With these policy language enhancements, you can now create more concise and precise policies to implement sophisticated permissions guardrails across your organization. For example, you can restrict access to specific resources with condition statements. The enhanced functionality maintains backward compatibility with existing SCPs, so no changes to current policies are required.
This feature is now available in all AWS commercial and AWS GovCloud (US) Regions.
To learn more about the enhanced SCP capabilities, see service control policies in the AWS Organizations User Guide and AWS blog.
Categories: general:products/aws-organizations,general:products/aws-govcloud-us,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Updates available for Microsoft 365 Apps for Current Channel [MC1255412]
![Updates available for Microsoft 365 Apps for Current Channel [MC1255412] 2 pexels eye4dtail 134402](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Publishing InfoPath Forms in SharePoint Online will not be allowed for all tenants [MC1255407]
![Publishing InfoPath Forms in SharePoint Online will not be allowed for all tenants [MC1255407] 3 pexels magda ehlers pexels 1329317](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Set a custom name for the OneDrive sync folder [MC1242782]
![(Updated) Set a custom name for the OneDrive sync folder [MC1242782] 4 pexels urlapovaanna 2957060](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Lists as a knowledge source for agents in SharePoint and OneDrive [MC1255409]
![Lists as a knowledge source for agents in SharePoint and OneDrive [MC1255409] 5 pexels sun god apolo 230380599 31233586](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Updates available for Microsoft 365 Apps for Current Channel [MC1255412] 2 pexels eye4dtail 134402](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-eye4dtail-134402-150x150.webp)
![Publishing InfoPath Forms in SharePoint Online will not be allowed for all tenants [MC1255407] 3 pexels magda ehlers pexels 1329317](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-magda-ehlers-pexels-1329317-150x150.webp)
![(Updated) Set a custom name for the OneDrive sync folder [MC1242782] 4 pexels urlapovaanna 2957060](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-urlapovaanna-2957060-150x150.webp)
![Lists as a knowledge source for agents in SharePoint and OneDrive [MC1255409] 5 pexels sun god apolo 230380599 31233586](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-sun-god-apolo-230380599-31233586-150x150.webp)
![(Updated) Microsoft Teams: New user setting to view incoming calls in a small window [MC1045221] 7 (Updated) Microsoft Teams: New user setting to view incoming calls in a small window [MC1045221]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-pixabay-144243-96x96.webp)