Is it possible to create such a SCP (Service Control Policy) and attach it to account which denies any new resources (infrastructure) launching within this account? Assuming that the account is part of AWS Organizations.
The question arises from the following confusions:
- can SCP restrict specific actions like launching infrastructure?
- can SCP be applied on the account level (not to the organizational one!)?