AWS Organizations configuration cannot use Service Control Policies

Where organizational guardrails are required, verify all-features mode and actual SCP coverage.

Description

CONSOLIDATED_BILLING limits AWS Organizations to consolidated billing and does not support Service Control Policies (SCPs). Use all features when common organizational permission limits are required.

SCPs limit member-account permissions rather than granting them. Enabling all features alone does not establish the required restrictions; verify the policy type and attachments too. SCPs do not apply to the management account or service-linked roles.

Potential impact

  • Missing common restrictions can leave inconsistent permissions across accounts.
  • Untested SCPs can also block legitimate operations.

Remediation

  • Plan migration to feature_set = "ALL". Invited accounts may need to approve it, and all-features mode cannot be reverted to consolidated billing only.
  • Enable the SCP policy type and attach required policies to the organization root, OUs or accounts. Test legitimate operations and restrictions in a test account before expanding coverage.

Examples

These examples compare organization feature settings. SCP definitions and attachments are separate.

Before

hcl
resource "aws_organizations_organization" "example" {
  feature_set = "CONSOLIDATED_BILLING"
}

After

hcl
resource "aws_organizations_organization" "example" {
  aws_service_access_principals = [
    "cloudtrail.amazonaws.com",
    "config.amazonaws.com",
  ]

  feature_set = "ALL"
}

Explanation:

  • Before: Consolidated billing mode cannot use SCPs or service integrations.
  • After: Enables all features and the specified service integrations. Verify actual SCP enablement, attachments and coverage separately.

References