AWS Tag Policies Don't Enforce Tag Presence — Here's What They Actually Do
AWS tag policies, commonly attached via AWS Organizations, standardize tag key casing and allowed values but do not verify whether resources are actually tagged at all. Resources created without any tags are considered 'unevaluated' rather than non-compliant, meaning they never appear as failures in compliance reports. This creates a significant blind spot: manually created resources — those most likely to lack tags — are invisible to the very reports designed to catch untagged resources. The gap compounds when tags serve as a resource index, since queries via the Resource Groups Tagging API or Cost Explorer return confident results with no indication that coverage may be incomplete. A separate layer, such as AWS Config rules or Service Control Policies, is needed to enforce tag presence at resource creation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in