Example SQL Queries
aws . organizations .describe_effective_policy
Description
Returns the contents of the effective policy for specified policy type and account. The effective policy is the aggregation of any policies of the specified type that the account inherits, plus any policy of that type that is directly attached to the account.
This operation applies only to policy types other than service control policies (SCPs).
For more information about policy inheritance, see Understanding management policy inheritance in the Organizations User Guide .
This operation can be called from any account in the organization.
Table Definition
Column Name Column Data Type
policy_type Required Input Column The type of policy that you want information about. You can specify one of the following values:
VARCHAR
target_id Input Column When you're signed in as the management account, specify the ID of the account that you want details about. Specifying an organization root or organizational unit (OU) as the target is not supported.
VARCHAR
_aws_profile Input Column The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.
STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) )
Show child fields _aws_profile.account_id The AWS account id
_aws_profile.assumed_role_arn The ARN of the assumed role
_aws_profile.name The unique name of the profile.
_aws_profile.organization Information about this profile's membership in the AWS organization.
Show child fields _aws_profile.organization.account_name The name of account speciifed by the organization
_aws_profile.organization.id The organization id
_aws_profile.organization.master_account Show child fields _aws_profile.organization.master_account.email The organization master account email address
_aws_profile.organization.master_account.id The organization master account id
_aws_profile.organization.parents[] Show child fields _aws_profile.organization.parents[].id The id of the parent
_aws_profile.organization.parents[].name The name of the parent
_aws_profile.organization.parents[].tags[] Show child fields _aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type The type of parent can be an organization unit or a root
_aws_profile.organization.tags[] Show child fields _aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type The type of profile, either 'credentials' or 'assumed_role'
_aws_profile.via_profile_name This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
effective_policy The contents of the effective policy.
STRUCT( "policy_content" VARCHAR, "last_updated_timestamp" TIMESTAMP_S, "target_id" VARCHAR, "policy_type" VARCHAR )
Show child fields effective_policy.last_updated_timestamp The time of the last update to this policy.
effective_policy.policy_content The text content of the policy.
effective_policy.policy_type The policy type.
effective_policy.target_id The account ID of the policy target.