'AccessDeniedException' When Rekognition Fails Due to Service Control Policy (SCP) Explicit Deny
'AccessDeniedException' When Rekognition Fails Due to Service Control Policy (SCP) Explicit Deny # AWS # AmazonRekognition # IAM # CloudSecurity Why AdministratorAccess cannot override organization guardrails in AWS Problem Your application calls DetectLabels in Amazon Rekognition . The IAM role has: AdministratorAccess Explicit rekognition:* permissions Verified trust relationship Yet the request fails with: AccessDeniedException: User is not authorized to perform: rekognition:DetectLabels IAM looks correct. The role is admin. Still denied. Clarifying the Issue If your account is part of AWS Organizations, an Organization-level Service Control Policy (SCP) may be blocking Rekognition. An SCP operates above IAM. It does not grant permissions. It defines the maximum permissions allowed within an account. If an SCP includes: An explicit Deny on rekognition:* A deny on specific regions A deny using NotActi...