AWS IAM Identity Center now supports network access controls for Identity Store

AWS IAM Identity Center Network Access Controls
AWS IAM Identity Center now supports network access controls for Identity Store, enabling you to restrict access to the Identity Store API and the SCIM API based on the network that requests originate from.
- Identity Store API: Require requests to arrive only through allowed VPC endpoints or specific source VPCs.
- SCIM API: Allow requests only from specific IP ranges.
- Different restrictions can be applied to each API within the same configuration.
Network access controls are optional and turned off by default. AWS services making requests on your behalf are exempt. Configure these controls using the Identity Store API through the AWS SDKs and AWS CLI. This feature is available in all AWS Regions where IAM Identity Center is offered.
What to do
- Review your current Identity Store API and SCIM API access configurations.
- Enable network access controls as needed to secure your Identity Store.
- Test your configurations to ensure they meet your security requirements.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



