Service control policies (SCP) syntax does not support the element 'Resource' with effect 'Allow'; only 'Deny' is supported here.
References:
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_syntax.html
In AWS Console -
In Terraform -
References:
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies.html
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/organizations_policy