组织 ORGANIZATIONS-SCP配置示例:阻止IAM用户和委托进行某些修改
时间:2025-06-19 11:02:53
阻止 IAM 用户和委托进行某些修改
使用此SCP阻止IAM用户和委托对组织内所有账号创建的资源共享进行修改。
{ "Version": "5.0", "Statement": [ { "Effect": "Deny", "Action": [ "ram:resourceShares:update", "ram:resourceShares:delete", "ram:resourceShares:associate", "ram:resourceShares:disassociate", "ram:resourceShares:associatePermission", "ram:resourceShares:disassociatePermission" ], "Resource": [ "ram::*:resourceShare:resource-id" ] } ] }
support.huaweicloud.com/usermanual-organizations/org_03_0081.html