Skip to main content

enabled_controls

Retrieves a list of enabled_controls in a region

Overview

Nameenabled_controls
TypeResource
Descriptionenabled_controls
Idawscc.controltower.enabled_controls

Fields

NameDatatypeDescription
target_identifierstringArn for Organizational unit to which the control needs to be applied
control_identifierstringArn of the control.
regionstringAWS region.

Methods

Currently only SELECT is supported for this resource resource.

Example

SELECT
region,
target_identifier,
control_identifier
FROM awscc.controltower.enabled_controls
WHERE region = 'us-east-1'

Permissions

To operate on the enabled_controls resource, the following permissions are required:

Create

controltower:ListEnabledControls,
controltower:GetEnabledControl,
controltower:GetControlOperation,
controltower:EnableControl,
controltower:TagResource,
organizations:UpdatePolicy,
organizations:CreatePolicy,
organizations:AttachPolicy,
organizations:DetachPolicy,
organizations:ListPoliciesForTarget,
organizations:ListTargetsForPolicy,
organizations:DescribePolicy

List

controltower:ListEnabledControls