SCP manipulation

Service control policies are the organization-wide permission ceiling: they cap what principals in member accounts may do, regardless of their IAM policies. From the management account (or a delegated admin), editing or detaching an SCP removes that ceiling, unblocking actions the org was relying on SCPs to deny.

Loosen a guardrail#

bash
aws organizations list-policies --filter SERVICE_CONTROL_POLICY
aws organizations update-policy --policy-id <scp-id> \
  --content '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}'
# or detach a restrictive SCP from an OU or account
aws organizations detach-policy --policy-id <scp-id> --target-id <ou-or-account>

Exploitation notes#

  • SCPs do not grant permissions, they bound them, so lifting an SCP only matters alongside IAM permissions in the target account, but it removes a control teams assume is holding.
  • This requires management-account access; it is a post-compromise move once you hold the org root, often paired with member account role.
  • Editing the FullAWSAccess baseline or attaching an allow-all policy is the broadest change and the most visible.

Tools#

  • AWS CLI (organizations update-policy / detach-policy).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more