Prevents the deletion of critical CloudWatch alarms, ensuring that monitoring alerts are not accidentally removed.
What this SCP does
This Service Control Policy (SCP) prevents the deletion of critical CloudWatch alarms, ensuring that monitoring alerts are not accidentally removed. This maintains your ability to detect and respond to operational events.
By blocking the deletion of CloudWatch alarms across the organization, this policy safeguards your monitoring infrastructure, ensuring that important alerts remain in place to notify you of potential issues and security incidents, even if a user accidentally attempts to remove them.
How to test this SCP works
To validate this SCP, try to create and then delete a CloudWatch alarm.
We expect the alarm creation to succeed, but deletion attempts to be denied with an AccessDenied error. This confirms that the SCP is preventing the removal of CloudWatch alarms, protecting your monitoring setup.