AccountScope
Configures the accounts within the administrator's AWS Organizations organization that the specified Firewall Manager administrator can apply policies to.
Contents
- Accounts
-
The list of accounts within the organization that the specified Firewall Manager administrator either can or cannot apply policies to, based on the value of
ExcludeSpecifiedAccounts
. IfExcludeSpecifiedAccounts
is set totrue
, then the Firewall Manager administrator can apply policies to all members of the organization except for the accounts in this list. IfExcludeSpecifiedAccounts
is set tofalse
, then the Firewall Manager administrator can only apply policies to the accounts in this list.Type: Array of strings
Length Constraints: Minimum length of 1. Maximum length of 1024.
Pattern:
^[0-9]+$
Required: No
- AllAccountsEnabled
-
A boolean value that indicates if the administrator can apply policies to all accounts within an organization. If true, the administrator can apply policies to all accounts within the organization. You can either enable management of all accounts through this operation, or you can specify a list of accounts to manage in
AccountScope$Accounts
. You cannot specify both.Type: Boolean
Required: No
- ExcludeSpecifiedAccounts
-
A boolean value that excludes the accounts in
AccountScope$Accounts
from the administrator's scope. If true, the Firewall Manager administrator can apply policies to all members of the organization except for the accounts listed inAccountScope$Accounts
. You can either specify a list of accounts to exclude byAccountScope$Accounts
, or you can enable management of all accounts byAccountScope$AllAccountsEnabled
. You cannot specify both.Type: Boolean
Required: No
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: