Help Center/ Organizations/ User Guide/ Managing SCPs/ Enabling or Disabling the SCP Type
Updated on 2026-08-25 GMT+08:00

Enabling or Disabling the SCP Type

Scenarios

To use SCPs for isolating and controlling account permissions, you must first enable the SCP policy type. Once enabled, the FullAccess policy is automatically attached to the root OU, all subordinate OUs, and every account within the organization.

If you decide to stop using SCPs, you can disable the policy type. This action automatically detaches all policies from every OU and account, though the SCPs themselves are not deleted.

Helpful links:

Enabling the SCP Type

Once the SCP type is enabled, SCPs are automatically applied to all OUs and accounts. However, you must manually enable SCP dry run.

Before you create and attach an SCP to OUs and accounts, you have to enable the SCP type from the organization's management account. After the SCP type is enabled, Organizations automatically attach the FullAccess policy (allowing for all operations) to all OUs and accounts.

  1. Log in to the Organizations console as an organization administrator or using the management account.
  2. On the Policies page, click Enable in the Operation column of the service control policies.
  3. In the displayed dialog box, select the check box and click OK.

    Figure 1 Enabling the SCP type

Disabling the SCP Type

If you no longer want to use SCPs to manage permissions for your organization, you can disable the SCP type from the organization's management account.

  • After the SCP type is disabled in an organization, all SCPs are automatically detached from all OUs and accounts in the organization. However, the SCPs are not deleted.
  • If the SCP type is disabled and then re-enabled, all entities in the organization will revert to being attached only to FullAccess. Attachments between entities and other SCPs will be lost; if you need to restore them, you must re-attach them.
  1. Log in to the Organizations console as an organization administrator or using the management account.
  2. On the Policies page, click Disable in the Operation column of the service control policies.

    Figure 2 Disabling the SCP type

  3. Click OK in the displayed dialog box.
  4. Return to the Policies page. If the status of SCPs is Disabled, SCPs are disabled.

Enabling SCP Dry Run

  1. On the Policies page, click Service control policies.

  2. In the Dry-Run tab, enable the policy dry run function in the upper-right corner of the policy list.

  3. Configure log transfer in policy dry run configuration.

    Select an OBS bucket to store policy dry run logs.

    • Select an OBS bucket from the current account:

      Select Your bucket and select an OBS bucket in your account from the drop-down list to store policy dry run logs. To store policy dry run logs in a specific folder within an OBS bucket, select the bucket and enter the OBS bucket prefix. The prefix corresponds to the folder name where the logs will be stored. If there are no OBS buckets in the current account, create one. For details, see Creating a Bucket.

    • Select an OBS bucket from another account:

      Select Other users' bucket and configure the region ID and bucket name. If you want to store the policy dry run logs in a folder in the OBS bucket, enter the bucket prefix. The prefix corresponds to the folder name where the logs will be stored. You need to first use the target account to grant the current account permissions on the relevant OBS bucket. For details, see Cross-Account Authorization.

    • If you specify an OBS bucket of the current account or another account when enabling SCP dry run, the Organizations service will create an empty file named OrganizationsWritabilityCheckFile in the OBS bucket. This file is used only to verify whether the OBS bucket can be written to.
    • When you enable SCP dry run, DryRunFullAccess is attached to all entities in the organization by default.

  4. Perform custom authorization.

    Create an Organizations cloud service agency: You can create an agency in Identity and Access Management (IAM) and configure custom authorization for the Organizations cloud service. The agency must include the minimum permissions required for policy dry runs to work properly: OBS permissions to query bucket region location and upload objects. For details about how to create an agency, see the Delegating Another Service for Resource Management.


    {
      "Version": "5.0",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "obs:bucket:getBucketLocation",
            "obs:object:putObject"
          ]
        }
      ]
    }
    Configure authorization for transferring policy dry run logs to an encrypted OBS bucket:
    • OBS buckets encrypted with SSE-OBS

      Select the target OBS bucket and no other operations are required.

    • OBS buckets encrypted with the default key of SSE-KMS

      Grant the KMS Administrator permission to the Organizations agency.

    • OBS buckets encrypted with a custom key of SSE-KMS

      Grant the KMS Administrator permission to the Organizations agency.

      If you choose to store policy dry run logs to an OBS bucket encrypted using a custom key of SSE-KMS in another account, you need to grant the KMS Administrator permission to the Organizations agency and set the permission to use the custom KMS key across accounts to encrypt the OBS bucket. For details, see Creating a Grant for a Custom Key.

  5. After the configuration is complete, click OK. The policy dry run is configured successfully.

    In the Dry-Run tab, if the Policy Dry-Run Enabled toggle is on, the function is enabled.

Updating SCP Dry Run

  1. On the Policies page, click Service control policies.

  2. In the Dry Run tab, click Update.

  3. In the displayed side pane, select where you want to transfer dry run logs, specify the settings, and click OK.

    If an administrator updates the OBS bucket or agency configurations for policy dry run, the changes take effect in up to 15 minutes.

Disabling SCP Dry Run

  1. On the Policies page, click Service control policies.

  2. In the Dry-Run tab, toggle off Policy Dry-Run Enabled.
  3. In the displayed dialog box, enter CONFIRM and click OK. The policy dry run function is disabled.

    • Enabling or disabling policy dry runs does not affect the attachments between entities and policies in the organization. After SCP dry runs are disabled, all entities remain attached to DryRunFullAccess, and their attachments to other SCPs are not lost. After SCP dry runs are re-enabled, these attachments remain unchanged.
    • Once policy dry runs are disabled, the update function for dry runs stops immediately, and policy dry run logs will no longer be generated.

Cross-Account Authorization

Grant cross-account permissions for OBS buckets to store policy dry run logs
  1. Log in to the OBS console using the authorizing account.
  2. Grant related OBS permissions to target accounts based on Creating a Custom Bucket Policy (JSON View).
  3. Configure the bucket policy by referring to the following example. The policy allows the authorized accounts to store files to the specified path of the OBS bucket. You need to configure the following parameters in a bucket policy:
    • ${account_id}: ID of the account to be authorized
    • ${agency_name}: name of the agency to be authorized
    • ${bucket_name}: name of the OBS bucket
    • ${folder_name}: name of the folder in the OBS bucket. If you do not specify a folder in the OBS bucket, delete this parameter.
    {
      "Statement": [
        {
          "Sid": "org-bucket-policy",
          "Effect": "Allow",
          "Principal": {
            "ID": [
              "domain/${account_id}:agency/${agency_name}"
            ]
          },
          "Action": [
            "PutObject",
            "GetBucketLocation"
          ]
        }
      ]
    }