Gateway Endpoint
Target of traffic for controlled data flow.
ENI
Elastic Network Interface (ENI): Virtual NIC
Route Tables
Routes to determine network traffic from subnet or gateway.
SCP
Service Control Policy
Part of AWS Organizations
Denies access to AWS services to member users. Non-members of your organization are not affected.
Is only restrictive. Grants no permissions.
By default, everything is enabled.
Effective permissions = SCP limitations + IAM access grants