ModifyAccountVpcEncryptionControl - Amazon Elastic Compute Cloud
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

ModifyAccountVpcEncryptionControl

Modifies the account-level VPC Encryption Control configuration. This sets the encryption control mode and resource exclusions that apply to the VPCs in your account. VPC Encryption Control enables you to enforce encryption for all data in transit within and between VPCs to meet compliance requirements.

For more information, see Enforce VPC encryption in transit in the Amazon VPC User Guide.

Request Parameters

The following parameters are for this specific action. For more information about required and optional parameters that are common to all actions, see Common Query Parameters.

DryRun

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

Type: Boolean

Required: No

EgressOnlyInternetGateway

Specifies whether to exclude egress-only internet gateway resource from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

ElasticFileSystem

Specifies whether to exclude Elastic File System service from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

InternetGateway

Specifies whether to exclude internet gateway resource from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

Lambda

Specifies whether to exclude Lambda service from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

Mode

The encryption mode for the account encryption control configuration.

Type: String

Valid Values: unmanaged | attempt-monitor | attempt-enforce

Required: No

NatGateway

Specifies whether to exclude NAT gateway resource from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

VirtualPrivateGateway

Specifies whether to exclude virtual private gateway resource from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

VpcLattice

Specifies whether to exclude VPC Lattice service from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

VpcPeering

Specifies whether to exclude VPC peering connection resource from account-level encryption enforcement.

Type: String

Valid Values: enable | disable

Required: No

Response Elements

The following elements are returned by the service.

accountVpcEncryptionControl

Information about the account-level VPC Encryption Control configuration.

Type: AccountVpcEncryptionControl object

requestId

The ID of the request.

Type: String

Errors

For information about the errors that are common to all actions, see Common Error Types.

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: