This SCP prevents users or roles in any affected account from creating Resource Access Shares using RAM that are shared with external principals outside the organization

Configuration template includes a CloudFormation custom resource to deploy into an AWS account.

    "Version": "2012-10-17",
    "Statement": [
            "Action": [
            "Resource": "*",
            "Effect": "Deny",
            "Condition": {
                "Bool": {
                    "ram:AllowsExternalPrincipals": "true"


