Amazon S3 Block Public Access now supports organization-level enforcement
Share
Services
Amazon S3 Block Public Access (BPA) now allows organization-level control through AWS Organizations, allowing you to standardize and enforce S3 public access settings across all accounts in your AWS organization through a single policy configuration.
S3 Block Public Access at the organization level uses a single configuration that controls all public access settings across accounts within your organization. When you attach the policy at the root or Organizational Unit (OU)-level of your organization, it propagates to all sub-accounts within that scope, and new member accounts automatically inherit the policy. Alternatively, you can choose to apply the policy to specific accounts for more granular control. To get started, navigate to the AWS Organizations console and use the "Block all public access" checkbox or JSON editor. Additionally, you can use AWS CloudTrail to audit or keep track of policy attachment as well as enforcement for member accounts.
This feature is available in the AWS Organizations console as well as AWS CLI/SDK, in all AWS Regions where AWS Organizations and Amazon S3 are supported, with no additional charges. For more information, visit the [AWS Organizations User Guide](https://docs.aws.amazon.com/organizations/latest/userguide/orgs%5Fmanage%5Fpolicies%5Fs3.html) and [Amazon S3 Block Public Access documentation](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html).
What else is happening at Amazon Web Services?
Read update
Services
Share
AWS Direct Connect announces new location in Hanoi, Vietnam
about 14 hours ago
Services
Share
Amazon SageMaker AI is now available in Asia Pacific (New Zealand)
about 16 hours ago
Services
Share
Amazon EC2 M8i instances are now available in additional Regions
about 16 hours ago
Services
Share
AWS Artifact enables access to previous versions of compliance reports
about 16 hours ago
Services
Share
Read update
Services
Share