AWS Organization SCP - Service Control Policy DEMO | Blacklist & Whitelist strategy

Sdílet
Vložit
  • čas přidán 29. 08. 2024
  • Learn #AWS Organization & Service Control Policy in detail:
    - Service Control Policy #SCP #DEMO
    - Blacklist & Whitelist strategy
    - How SCP works with IAM
    - Applying SCP at Root & Organizational Unit
    - SCP further reading - docs.aws.amazo...
    - IAM Video -- bit.ly/2JYF1MT
    - Organizations Video -- bit.ly/2YEml93
    - SCP examples -- amzn.to/2wbRqEN
    #######################################################
    HOW TO GET benefited from KNOWLEDGEINDIA to learn AWS
    #######################################################
    #AWS #Videos to learn in #EASY & #PRACTICAL manner:
    AWS Security: bit.ly/2Rj5yWI
    AWS Networking: bit.ly/2FbQoxq
    AWS Pricing: bit.ly/2KQysMA
    AWS Automation: bit.ly/2KkW8cm
    AWS Interview Questions: bit.ly/2IlLgcj
    -------------------------------------------------------
    AWS SysOps Admin: bit.ly/2RiuY6I
    AWS Solutions Architect: bit.ly/2WKpYZV
    +++++++++++++++++++++++++++++++++++++++++++++++++++++++
    SUBSCRIBE to CZcams channel: / knowledgeindia
    Watch our videos in correct order: bit.ly/2GVzLti
    Connect on LinkedIn, receive AWS updates & Practical Scenario Questions - bit.ly/2XC5bZg
    If you have got benefited, you can support us on PATREON: bit.ly/2TzxTbb
    Join AWS Practical Learning Group on LinkedIn: bit.ly/2Vx7aOi
    SUBSCRIBE to our blog for AWS exercises & case-studies: aws-tutorials....
    +++++++++++++++++++++++++++++++++++++++++++++++++++++++
    Facebook - AWStutorials
    Twitter - bit.ly/2RyuN9R
    We try our best to answer most of the COMMENTS within 24 hours. Please write your appreciation/feedback below.
    +++++++++++++++++++++++++++++++++++++++++++++++++++++++

Komentáře • 71

  • @railwayaspirant424
    @railwayaspirant424 Před 5 lety +6

    Superb explanation. It is best channel for aws, such a knowledge person who is delivering lectures in the channel. I can gaurentee anyone that once you go through any video you don't have doubts on particular topic. Videos helped me clearing aws sysops and solution architect associate certifications. Should highly recommend this channel anyone who is new to aws and want to master in it.
    Keep posting videos on different services in aws...would appreciate channel for providing such a worthy content at a free of cost.

    • @knowledgeindia
      @knowledgeindia  Před 5 lety

      Thanks a lot Pavan for your kind words. Please do write on LinkedIn as well. :)

    • @jacktoby1907
      @jacktoby1907 Před 3 lety

      @Roland Arjun I would suggest flixzone. You can find it on google =)

    • @zaviershiloh433
      @zaviershiloh433 Před 3 lety

      @Jack Toby yea, have been using FlixZone for months myself =)

  • @wysefavor
    @wysefavor Před 2 lety +1

    This is AWESOME!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

  • @siddharthtyagi1254
    @siddharthtyagi1254 Před 2 lety +2

    After learning soo many things from this channel, i can say this is one of the best channel for cloud. ❤️

    • @knowledgeindia
      @knowledgeindia  Před 2 lety

      Glad you think so! Please share it with more people in your circle.

  • @Techie-time
    @Techie-time Před 2 lety +1

    I came across your channel around 3 years back and made use of your videos to consistently clear my concept. You are superb. As a token of thanks I have made the payment. Looking forward to good videos from your channel.

  • @macg-mariam1179
    @macg-mariam1179 Před 3 lety +1

    Good video. Just remember it is not possible to use peering connection to send traffic to the internet. Peering connection allows you to send traffic between peered vpcs and not use vpc with internet gateway in one of the vpcs by traffic originating in other vpcs.

  • @AmitPawar-oj3yw
    @AmitPawar-oj3yw Před rokem +1

    Thanks Sir.. Your videos really helps in getting clear understanding of the topic.

  • @ritviksaxena1418
    @ritviksaxena1418 Před 4 lety

    thanks so much ... ur videos not just focus on the basic stuff but also implementing the advance stuff on the services ...i really love the work u put here ....

    • @knowledgeindia
      @knowledgeindia  Před 4 lety

      Glad you like them! Do share with your friends as well :)

  • @adarshchaurasia4347
    @adarshchaurasia4347 Před rokem +1

    Love the way how you explain 👍

  • @venkatabhavan2430
    @venkatabhavan2430 Před 5 lety +2

    Very helpful very informative. Thank you so much for sharing your knowledge.

  • @rajeevsinha2632
    @rajeevsinha2632 Před 3 lety +1

    Very informative video, You are such a great teacher. You nicely explained the concepts of SCP. Thank for your effort.

  • @TheDocValerian
    @TheDocValerian Před 2 lety +1

    very good and clear explanation. good video to study.

  • @maryperrare6944
    @maryperrare6944 Před 2 lety +1

    fantastic

  • @alammahtab27
    @alammahtab27 Před 3 lety

    Great knowldge and simple way to explain so that students can get a logical way to think & implement, surely recommed this to anyone who wants to stat on AWS. Many thanks

    • @knowledgeindia
      @knowledgeindia  Před 3 lety

      Thanks mahtab . 👍 Do share this with your friends and help them.

  • @amitpawar1677
    @amitpawar1677 Před rokem +1

    Nicely explained sir.. Thanks for the session..

  • @vamsikrishna2330
    @vamsikrishna2330 Před 4 lety +2

    Thank a lot ... really good video, makes things very clear 👏🏻👏🏻👏🏻👏🏻👏🏻👏🏻👏🏻

  • @manishsharma9490
    @manishsharma9490 Před 3 lety +1

    very nice explanation with demo.. thank you so much!!

  • @shan786-sb
    @shan786-sb Před 3 lety +1

    Another superb lecture.... Thanks man...

    • @knowledgeindia
      @knowledgeindia  Před 3 lety

      Thanks for your appreciation. You can support our initiative of Free Practical Cloud Tutorials by sharing this video with your friends on Social channels, whatsapp etc.
      If it helped you solve a problem and you would like to applaud us, click the Applaud button :)
      For regular 1-1 interaction with me, check our Membership - czcams.com/channels/zpHRBVnkzBfSsXostYuW1g.htmljoin
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • @Techie-time
    @Techie-time Před 2 lety +1

    Thanks!

    • @knowledgeindia
      @knowledgeindia  Před 2 lety

      Thank you 👍I hope you continue to learn from our videos.

  • @danishsahibole3055
    @danishsahibole3055 Před 2 lety +1

    Great videos bro ......

    • @knowledgeindia
      @knowledgeindia  Před 2 lety

      Thank you 👍I hope you continue to learn from our videos.

  • @ig2947
    @ig2947 Před 5 lety +2

    Brilliant video.. thanks a lot

  • @preetbenipal1034
    @preetbenipal1034 Před 3 lety +1

    very well explained

  • @vedanti-vidhan4766
    @vedanti-vidhan4766 Před 3 lety +1

    superb video !!

  • @harirocking1530
    @harirocking1530 Před rokem

    nyc explanation

  • @martijnweterings9721
    @martijnweterings9721 Před 4 lety +1

    Thank you! Nice demo. Like!

    • @knowledgeindia
      @knowledgeindia  Před 4 lety

      Thanks a lot. You can help us by sharing the videos with your friends on LinkedIn/Facebook.

  • @binayokbhowmik9458
    @binayokbhowmik9458 Před 5 lety +2

    Superb explanation for scp. My concepts are cleared now. Thanks for this wonderful material.
    Sir, would you provide any aws sysops training ?

    • @knowledgeindia
      @knowledgeindia  Před 5 lety

      Thanks a lot. we do have a playlist for sysops.. In addition, there would an upcoming training batch after a while..

  • @truptikagale9016
    @truptikagale9016 Před 3 lety +1

    Sir, your videos are very helpful.Thank you . Could you please make video on AWS cognito and identity federation service in AWS?

    • @knowledgeindia
      @knowledgeindia  Před 3 lety +1

      Sure, will do that. Please share this and support us

  • @AsmithaSP
    @AsmithaSP Před 4 lety +1

    Thanks. nicely explained

  • @ebinpissac
    @ebinpissac Před 5 lety +1

    actually great video. But I think u need to speed up the video to save time. i played it in 1.35x but still understandable well.

    • @knowledgeindia
      @knowledgeindia  Před 5 lety

      alright .. glad that you increased the speed.. Please do check out other videos on our channel as well for the same type of content..

    • @lijie6431
      @lijie6431 Před 5 lety

      1.75x speed for me. Great content still.

  • @SoumyaDassrd
    @SoumyaDassrd Před rokem +1

    Hey,
    Correct yourself : SCPs affect only member accounts in the organization. They have no effect on users or roles in the management account 10:20

  • @tbugl5548
    @tbugl5548 Před 3 lety +1

    Great content and well explained! Could you please move the logo to bottom right?

    • @knowledgeindia
      @knowledgeindia  Před 3 lety

      Thanks for your appreciation. You can support our initiative of Free Practical Cloud Tutorials by sharing this video with your friends on Social channels, whatsapp etc.
      If it helped you solve a problem and you would like to applaud us, click the Applaud button :)
      For regular 1-1 interaction with me, check our Membership - czcams.com/channels/zpHRBVnkzBfSsXostYuW1g.htmljoin
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • @shamstabrez2986
    @shamstabrez2986 Před 2 lety

    toh apka kehne ka ye mtlb h k jaise root pr laga hua policy and ou pr laga hua policy dono hi ki2 mein phle inherit hua ab dono k scp milakr jo common hoga woh ki2 pr apply hojyga

  • @shamstabrez2986
    @shamstabrez2986 Před 2 lety

    this kind of video should make on notepad with diagrams konse acoount k andar kya h konsa ou h sb confusion hora

  • @sandeepgupta6980
    @sandeepgupta6980 Před 4 lety +1

    Good job, bud. Try not to say "go ahead" too much. Cheers!

  • @charleskamalanand8644
    @charleskamalanand8644 Před 4 lety +1

    Great video again. I just started to watch all your video.
    I have a question on organisation.
    In case if a child root account gets compromised and first thing he may do is disable cloudtrail which could be restricted due to scp.
    But what if he removes the child account from the organisation and would it be possible him to disable cloudtrail and run resources he likes? Would scp restrict child organisation leaving from its organisation?

    • @knowledgeindia
      @knowledgeindia  Před 4 lety

      Yes that's also possible. Look at example scp in documentation

    • @charleskamalanand8644
      @charleskamalanand8644 Před 4 lety

      Thanks KI, would it be possible if you share the link as Aws documentation which I saw did have scp which restricts child account leaving organisation.

  • @anannyakatti
    @anannyakatti Před 4 lety +1

    in this video, post 21 minutes you have given an example of VPC peering and the traffic flowing outside with the help of peered VPC IGW. but AFAIK this is not possible in AWS. AWS rejects ede to edge routing. Can you please clarify

    • @knowledgeindia
      @knowledgeindia  Před 4 lety +1

      Anand, I heard the part again. I have said that it can go via other vpc which has internet connection. I did not say you can directly use igw of other vpc. To use other vpc we will have to implement proxy in that vpc. I hope that helps. 😊😊
      You can support our initiative by sharing with your friends and colleagues..

    • @anannyakatti
      @anannyakatti Před 4 lety +1

      @@knowledgeindia Definitely. you have done a fantastic job by providing small videos on each of the topic. Really appreciate.

  • @debashishbose8423
    @debashishbose8423 Před 2 lety

    When we remove the explicit deny for IGW and there is no explicit allow then the default deny should apply right? How are we able to create the IGW in that case?

    • @karthikeyanc749
      @karthikeyanc749 Před rokem

      But we do have full access along with that, this is an additional SCP attached

  • @RaviPrkash1987
    @RaviPrkash1987 Před 4 lety

    How to check at account level for applied SCP policies other levels OU and root level..

  • @manikandank2125
    @manikandank2125 Před měsícem

    Hey Bro - What incase I don’t want this deny policy in one of AWS account which is in the lower place hierarchy?

    • @knowledgeindia
      @knowledgeindia  Před měsícem

      any SCP applied above will flow downwards. If you don't want it on an account, then you need to probably move that account to a separate OU.

  • @abhaygodbole9194
    @abhaygodbole9194 Před 4 lety

    Hello Sir,
    Very informative... I am trying to setup following scenario...
    => Root --> SCP--> FullAccess
    => AWSExperts (OU) --> FullAccess (inherited)
    => Development (Account) --> FullAccess (inherited) --> DenyEC2Termination (Custom SCP)
    => Admins (Group) --> Admin (IAM Policy)
    => Abhay (IAM User)
    => EC2Users (Group) --> EC2FullAccess (IAM Policy)
    => EC2User-1 (IAM User) --> EC2FullAccess (Inherited)
    The following DenyEC2Termination SCP denies termination for the EC2User-1:
    {
    "Version": "2012-10-17",
    "Statement": [
    {
    "Sid": "Statement1",
    "Effect": "Deny",
    "Action": [
    "ec2:TerminateInstances"
    ],
    "Resource": [
    "arn:aws:iam::967709585020:user/EC2User-1"
    ]
    }
    ]
    }
    Issue is when I logged in as EC2User-1 I am able to terminate the EC2 instance. Expected is, it should deny this action.
    Initially I tried with Resource "*" , it was working when I logged in as Root Development account. Its not working for specific IAM User. Where I am going wrong?
    Please guide
    Thanks

  • @Amarjeet-fb3lk
    @Amarjeet-fb3lk Před 4 lety

    Does scp rules are applied to IAM users which are created by child accounts root users on which SCP policies are applied?

  • @krishnakanth5993
    @krishnakanth5993 Před 4 lety

    I had watched your AWS organization and switching to different roles(Accounts) videos. You had made it like 3 or 4 parts. At this time i didn't find those videos. can you please provide those videos.

  • @maheswari.n5303
    @maheswari.n5303 Před 4 lety

    which user we will login to the ec2 instance in real time production environment in an organization

    • @knowledgeindia
      @knowledgeindia  Před 4 lety

      an OS level user and it depends on the OS of your EC2.