Control: AWS > IAM > Group > Policy Attachments > Approved
Configure AWS IAM group policies binding Approved
checking. This policy defines whether to verify the IAM group attached policies are approved (per Approved > Compiled Rules
), as well as the subsequent action to take on unapproved items. If set to "Enforce: Delete unapproved", any unapproved attached policy will be removed.
Resource Types
This control targets the following resource types:
Primary Policies
The following policies can be used to configure this control:
Category
In Your Workspace
Developers
- tmod:@turbot/aws-iam#/control/types/groupPolicyAttachmentsApproved
- tmod:@turbot/turbot#/control/categories/resourceApproved
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-iam#/control/types/groupPolicyAttachmentsApproved"
Get Controls
Control Type URI
Category URI
GraphQL
CLI