Class: Aws::ConfigService::Types::OrganizationAccessDeniedException
- Inherits:
-
EmptyStructure
- Object
- EmptyStructure
- Aws::ConfigService::Types::OrganizationAccessDeniedException
- Defined in:
- lib/aws-sdk-configservice/types.rb
Overview
For ‘PutConfigurationAggregator` API, you can see this exception for the following reasons:
-
No permission to call ‘EnableAWSServiceAccess` API
-
The configuration aggregator cannot be updated because your Amazon Web Services Organization management account or the delegated administrator role changed. Delete this aggregator and create a new one with the current Amazon Web Services Organization.
-
The configuration aggregator is associated with a previous Amazon Web Services Organization and Config cannot aggregate data with current Amazon Web Services Organization. Delete this aggregator and create a new one with the current Amazon Web Services Organization.
-
You are not a registered delegated administrator for Config with permissions to call ‘ListDelegatedAdministrators` API. Ensure that the management account registers delagated administrator for Config service principal name before the delegated administrator creates an aggregator.
For all ‘OrganizationConfigRule` and `OrganizationConformancePack` APIs, Config throws an exception if APIs are called from member accounts. All APIs must be called from organization management account.