> For the complete documentation index, see [llms.txt](https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/1.-iam-shen-fen-shi-bie-yu-fang-wen-kong-zhi/privileged-access-management-te-quan-fang-wen-guan-li/shi-yong-scp-xian-zhi-gen-yong-hu-de-xing-wei.md).

# 使用SCP限制根用户的行为

1. 打开控制台的AWS Organizations。
2. 打开菜单AWS accounts，打开**Root**也就是最顶端的组织；
3. 在Policies页签下面，Service control policies，点击Attach；
4. 创建一个新的策略：Deny-Root-Actions，内容填写

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Deny-Root-Actions",
      "Effect": "Deny",
      "Action": [
        "*"
      ],
      "Resource": [
        "*"
      ],
      "Condition": {
        "ArnLike": {
          "aws:PrincipalArn": [
            "arn:aws:iam::*:root"
          ]
        }
      }
    }
  ]
}
```

也可以加上限制条件，比如有MFA的情况可以使用root，其他情况拒绝：

```
{
  "Version": "2012-10-17",
  "Statement": [
  {
    "Sid": "DenyAllForRootIfNoMFA",
    "Effect": "Deny",
    "Action": "*",
    "Resource": "*",
    "Condition": {
      "BoolIfExists": { "aws:MultiFactorAuthPresent": "false" },
      "StringLike": { "aws:PrincipalArn": ["arn:aws:iam::*:root"] }
    }
  }]
}
```

5. 绑定这个新创建的策略到Root上则完成通过SCP限制根用户的行为。

<br>
