Updated on 2026-08-25 GMT+08:00

NCP Introduction

What Are Network Control Policies?

Network control policies (NCPs) are organization-based guardrail policies. They are used to control the access permission boundaries of VPC endpoints. You can attach those policies to organizations, OUs, or member accounts. When an NCP is attached to an organization or OU, all member accounts within that organization or OU must comply with this policy when they initiate access through VPC endpoints. When an NCP is attached to a single member account, this policy takes effect only for that account's VPC endpoint access.

Helpful links:

  • NCP Principles: NCP types, how NCPs work, and the relationship between NCPs and IAM policies
  • NCP Syntax: NCP structure and parameters

Testing NCP Effects

Before applying an NCP to your production environment, it is strongly recommended that you thoroughly design and test the system using test accounts, a test environment, and test cases. This helps avoid unnecessary impact on the use of service resources in the production environment. You need to fully verify the NCP in the test environment to ensure that the use of service resources is not interrupted unexpectedly.

Tasks Not Restricted by NCPs

You cannot use NCPs to restrict the following tasks:

  • Requests that are not initiated through a VPCEP.

Temporary security credentials obtained by new APIs used for accessing APIs of cloud services that support NCPs are restricted by NCPs.

Helpful Links

For details about the differences in access control between IAM and Organizations, see What Are the Differences in Access Control Between IAM and Organizations?