Class: Aws::ConfigService::Types::OrganizationAccessDeniedException

Inherits:
EmptyStructure
  • Object
show all
Defined in:
lib/aws-sdk-configservice/types.rb

Overview

For ‘PutConfigurationAggregator` API, you can see this exception for the following reasons:

  • No permission to call ‘EnableAWSServiceAccess` API

  • The configuration aggregator cannot be updated because your Amazon Web Services Organization management account or the delegated administrator role changed. Delete this aggregator and create a new one with the current Amazon Web Services Organization.

  • The configuration aggregator is associated with a previous Amazon Web Services Organization and Config cannot aggregate data with current Amazon Web Services Organization. Delete this aggregator and create a new one with the current Amazon Web Services Organization.

  • You are not a registered delegated administrator for Config with permissions to call ‘ListDelegatedAdministrators` API. Ensure that the management account registers delagated administrator for Config service principal name before the delegated administrator creates an aggregator.

For all ‘OrganizationConfigRule` and `OrganizationConformancePack` APIs, Config throws an exception if APIs are called from member accounts. All APIs must be called from organization management account.