AWS Security ChangesHomeSearch

AWS organizations: RCP service list expanded and resource-owner account semantics clarified

Service: organizations · 2026-09-27 · Documentation medium

File: organizations/latest/userguide/orgs_manage_policies_rcps.md · Type: authz

Summary

Adds many AWS services to the list of services that support Resource Control Policies (RCPs) and corrects the description of which account's RCPs apply, changing 'calling principal account' to 'resource owner's account'.

Security assessment

RCPs are an authorization boundary control. The correction clarifies that the resource owner's account RCPs (not the caller's) govern access, which is important for correctly reasoning about cross-account authorization enforcement. No specific vulnerability is referenced.

Evidence

  * RCPs apply to the resources that are authorized as part of an operation request. These resources can be found in the “Resource type” column of the Action table in the [Service Authorization Reference](https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html#actions_table). If a resource is specified in the "Resource type" column, then the RCPs of the resource owner's account are applied.

Diff

diff --git a/organizations/latest/userguide/orgs_manage_policies_rcps.md b/organizations/latest/userguide/orgs_manage_policies_rcps.md
index 5b3d41f2c..520fbf9a8 100644
--- a//organizations/latest/userguide/orgs_manage_policies_rcps.md
+++ b//organizations/latest/userguide/orgs_manage_policies_rcps.md
@@ -57,0 +58,6 @@ RCPs apply to actions for the following AWS services:
+  * [Amazon AppStream](https://docs.aws.amazon.com/appstream2) `(prefix:appstream)`
+
+  * [Amazon Aurora DSQL](https://docs.aws.amazon.com/aurora-dsql) `(prefix:dsql)`
+
+  * [Amazon Cloud Directory](https://docs.aws.amazon.com/clouddirectory) `(prefix:clouddirectory)`
+
@@ -83,0 +90,4 @@ RCPs apply to actions for the following AWS services:
+  * [Amazon Elastic Container Registry Public](https://docs.aws.amazon.com/AmazonECR/latest/public) `(prefix:ecr-public)`
+
+  * [Amazon GameLift Servers](https://docs.aws.amazon.com/gamelift) `(prefix:gamelift)`
+
@@ -93,0 +104,2 @@ RCPs apply to actions for the following AWS services:
+  * [Amazon Personalize](https://docs.aws.amazon.com/personalize) `(prefix:personalize)`
+
@@ -97,0 +110,2 @@ RCPs apply to actions for the following AWS services:
+  * [Amazon Simple Workflow Service](https://docs.aws.amazon.com/amazonswf/latest/developerguide) `(prefix:swf)`
+
@@ -108 +122 @@ RCPs apply to actions for the following AWS services:
-  * [Amazon AppStream](https://docs.aws.amazon.com/appstream2) `(prefix:appstream)`
+  * [Amazon WorkSpaces](https://docs.aws.amazon.com/workspaces) `(prefix:workspaces)`
@@ -111,0 +126,10 @@ RCPs apply to actions for the following AWS services:
+  * [AWS Auto Scaling](https://docs.aws.amazon.com/autoscaling/plans/userguide) `(prefix:autoscaling-plans)`
+
+  * [AWS Budgets](https://docs.aws.amazon.com/cost-management/latest/userguide/budgets-managing-costs.html) `(prefix:budgets)`
+
+  * [AWS Cloud Map](https://docs.aws.amazon.com/cloud-map) `(prefix:servicediscovery)`
+
+  * [AWS CloudTrail Data Service](https://docs.aws.amazon.com/awscloudtraildata/latest/APIReference) `(prefix:cloudtrail-data)`
+
+  * [AWS CodeArtifact](https://docs.aws.amazon.com/codeartifact) `(prefix:codeartifact)`
+
@@ -117,0 +142,2 @@ RCPs apply to actions for the following AWS services:
+  * [AWS Compute Optimizer](https://docs.aws.amazon.com/compute-optimizer) `(prefix:compute-optimizer)`
+
@@ -121,0 +148,2 @@ RCPs apply to actions for the following AWS services:
+  * [AWS Firewall Manager](https://docs.aws.amazon.com/waf/latest/developerguide/fms-chapter.html) `(prefix:fms)`
+
@@ -125,0 +154,2 @@ RCPs apply to actions for the following AWS services:
+  * [IAM Roles Anywhere](https://docs.aws.amazon.com/rolesanywhere/latest/userguide) `(prefix:rolesanywhere)`
+
@@ -133,0 +164,2 @@ RCPs apply to actions for the following AWS services:
+  * [AWS Resource Groups](https://docs.aws.amazon.com/ARG/latest/userguide) `(prefix:resource-groups)`
+
@@ -143,0 +176,2 @@ RCPs apply to actions for the following AWS services:
+  * [AWS User Notifications](https://docs.aws.amazon.com/notifications) `(prefix:notifications)`
+
@@ -145,0 +180,2 @@ RCPs apply to actions for the following AWS services:
+  * [AWS X-Ray](https://docs.aws.amazon.com/xray) `(prefix:xray)`
+
@@ -175 +211 @@ RCPs are a type of AWS Identity and Access Management (IAM) policy. They are mos
-  * RCPs apply to the resources that are authorized as part of an operation request. These resources can be found in the “Resource type” column of the Action table in the [Service Authorization Reference](https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html#actions_table). If a resource is specified in the "Resource type" column, then the RCPs of the calling principal account are applied. For example, `s3:GetObject` authorizes the object resource. Whenever a `GetObject` request is made, an applicable RCP will apply to determine whether the requesting principal can invoke the `GetObject` operation. An _applicable RCP_ is an RCP that has been attached to an account, to an organizational unit (OU), or to the root of the organization that owns the resource being accessed.
+  * RCPs apply to the resources that are authorized as part of an operation request. These resources can be found in the “Resource type” column of the Action table in the [Service Authorization Reference](https://docs.aws.amazon.com/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html#actions_table). If a resource is specified in the "Resource type" column, then the RCPs of the resource owner's account are applied. For example, `s3:GetObject` authorizes the object resource. Whenever a `GetObject` request is made, an applicable RCP will apply to determine whether the requesting principal can invoke the `GetObject` operation. An _applicable RCP_ is an RCP that has been attached to an account, to an organizational unit (OU), or to the root of the organization that owns the resource being accessed.