NCP Introduction
What Are Network Control Policies?
Network control policies (NCPs) are organization-based guardrail policies. They are used to control the access permission boundaries of VPC endpoints. You can attach those policies to organizations, OUs, or member accounts. When an NCP is attached to an organization or OU, all member accounts within that organization or OU must comply with this policy when they initiate access through VPC endpoints. When an NCP is attached to a single member account, this policy takes effect only for that account's VPC endpoint access.
Helpful links:
- NCP Principles: NCP types, how NCPs work, and the relationship between NCPs and IAM policies
- NCP Syntax: NCP structure and parameters
Testing NCP Effects
Before applying an NCP to your production environment, it is strongly recommended that you thoroughly design and test the system using test accounts, a test environment, and test cases. This helps avoid unnecessary impact on the use of service resources in the production environment. You need to fully verify the NCP in the test environment to ensure that the use of service resources is not interrupted unexpectedly.
Tasks Not Restricted by NCPs
You cannot use NCPs to restrict the following tasks:
- Requests that are not initiated through a VPCEP.
- Tokens obtained by old APIs used for accessing APIs of cloud services that support NCPs (in most cases).
Temporary security credentials obtained by new APIs used for accessing APIs of cloud services that support NCPs are restricted by NCPs.
Helpful Links
For details about the differences in access control between IAM and Organizations, see What Are the Differences in Access Control Between IAM and Organizations?
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot