Description
CONSOLIDATED_BILLING limits AWS Organizations to consolidated billing and does not support Service Control Policies (SCPs). Use all features when common organizational permission limits are required.
SCPs limit member-account permissions rather than granting them. Enabling all features alone does not establish the required restrictions; verify the policy type and attachments too. SCPs do not apply to the management account or service-linked roles.
Potential impact
- Missing common restrictions can leave inconsistent permissions across accounts.
- Untested SCPs can also block legitimate operations.
Remediation
- Plan migration to
feature_set = "ALL". Invited accounts may need to approve it, and all-features mode cannot be reverted to consolidated billing only. - Enable the SCP policy type and attach required policies to the organization root, OUs or accounts. Test legitimate operations and restrictions in a test account before expanding coverage.
Examples
These examples compare organization feature settings. SCP definitions and attachments are separate.
Before
hcl
resource "aws_organizations_organization" "example" {
feature_set = "CONSOLIDATED_BILLING"
}
After
hcl
resource "aws_organizations_organization" "example" {
aws_service_access_principals = [
"cloudtrail.amazonaws.com",
"config.amazonaws.com",
]
feature_set = "ALL"
}
Explanation:
- Before: Consolidated billing mode cannot use SCPs or service integrations.
- After: Enables all features and the specified service integrations. Verify actual SCP enablement, attachments and coverage separately.