AWS organizations: Adds note on service-prefix:ALL_SUPPORTED wildcard for tag policy enforcement
Summary
Adds a note explaining that the `service-prefix:ALL_SUPPORTED` wildcard can be used in the `enforced_for` field to enable enforcement for all supported resource types of a service, but not across all services.
Security assessment
Tag policy enforcement is a governance/compliance control. The note documents a scoping wildcard and its limits, which is security-adjacent configuration guidance but not tied to a specific vulnerability.
Evidence
For a service that supports enforcement, you can specify the ``service-prefix`:ALL_SUPPORTED` wildcard in the `enforced_for` field to enable enforcement for all of that service's supported resource types. For example, `rds:ALL_SUPPORTED` applies to all supported Amazon RDS resource types. You can't use a wildcard to specify all services, or to specify a resource type across all services.
Diff
diff --git a/organizations/latest/userguide/orgs_manage_policies_supported-resources-enforcement.md b/organizations/latest/userguide/orgs_manage_policies_supported-resources-enforcement.md index 228dc893c..b59b8702c 100644 --- a//organizations/latest/userguide/orgs_manage_policies_supported-resources-enforcement.md +++ b//organizations/latest/userguide/orgs_manage_policies_supported-resources-enforcement.md @@ -10,0 +11,4 @@ The following services and resource types support enforcement with tag policies: +###### Note + +For a service that supports enforcement, you can specify the ``service-prefix`:ALL_SUPPORTED` wildcard in the `enforced_for` field to enable enforcement for all of that service's supported resource types. For example, `rds:ALL_SUPPORTED` applies to all supported Amazon RDS resource types. You can't use a wildcard to specify all services, or to specify a resource type across all services. +