Service control policies are the organization-wide permission ceiling: they cap what principals in member accounts may do, regardless of their IAM policies. From the management account (or a delegated admin), editing or detaching an SCP removes that ceiling, unblocking actions the org was relying on SCPs to deny.
Loosen a guardrail#
aws organizations list-policies --filter SERVICE_CONTROL_POLICY
aws organizations update-policy --policy-id <scp-id> \
--content '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}'
# or detach a restrictive SCP from an OU or account
aws organizations detach-policy --policy-id <scp-id> --target-id <ou-or-account>
Exploitation notes#
- SCPs do not grant permissions, they bound them, so lifting an SCP only matters alongside IAM permissions in the target account, but it removes a control teams assume is holding.
- This requires management-account access; it is a post-compromise move once you hold the org root, often paired with member account role.
- Editing the FullAWSAccess baseline or attaching an allow-all policy is the broadest change and the most visible.
Tools#
- AWS CLI (
organizations update-policy/detach-policy).