IAM Identity Center Adds Network Controls for Identity Store
New network access controls for Identity Store let you restrict API access by VPC endpoint or IP range.
Editorial summary and commentary based on the original from AWS What's New. Read the original
“Apply network controls to Identity Store APIs where it matters, without breaking existing workflows.”
What changed
AWS IAM Identity Center now provides optional network access controls for the Identity Store service. You can restrict access to the Identity Store API and the SCIM API based on where requests originate: allowed VPC endpoints, specific source VPCs, or defined IP ranges. These controls are off by default and apply independently to each API.
Technical context
IAM Identity Center centralizes SSO configuration across AWS accounts and applications. The Identity Store holds user and group data used by this service. Previously, network access to Identity Store APIs was unrestricted unless you applied external safeguards. Now, you can configure these controls directly through Identity Store settings.
Key points from the source
- Scope: Controls apply to Identity Store API and SCIM API.
- Options: Allow requests only from specific VPC endpoints, source VPCs, or IP ranges.
- Granularity: You can set different rules per API within the same configuration.
- Exemptions: Requests made by AWS services on your behalf are always allowed.
- Availability: Supported in all Regions where IAM Identity Center is offered.
Why it matters
This change helps you reduce attack surface for Identity Store operations. By limiting API access to known, trusted networks, you can mitigate risks if credentials are exposed. It also gives you finer control without requiring changes to application logic or service dependencies.
In practice: This is useful for environments that follow strict network segmentation policies or need to meet compliance mandates around API access control.
Implementation notes
The source does not provide specific implementation steps, pricing details, or quota information. You configure these controls programmatically via the Identity Store API using AWS SDKs or the AWS CLI. No AWS Management Console support is mentioned.
Watch out: Because this feature uses API-driven configuration, you will need automation or manual scripts to deploy and maintain network policies across accounts or organizations.
Cost and operations
The source does not disclose any additional costs associated with enabling or maintaining network access controls. Operational impact will depend on how strictly you define allowed networks and how often you need to update them.
Security and reliability
No specific security or reliability details are provided. The feature appears to rely on existing AWS networking mechanisms (VPC endpoints, IP filtering) for enforcement. The exemption for AWS-service-made requests suggests that service-to-service communication remains unaffected.
Limits and trade-offs
The following details are not provided in the source:
- Pricing or cost implications
- Service quotas or limits
- Regional availability constraints beyond "where IAM Identity Center is offered"
- Performance impact from network filtering
- Support for AWS Management Console
As a result, you should test in a non-production environment before widespread adoption.
Bottom line
Network access controls for Identity Store give you additional, granular ways to secure user and group management APIs. This is a incremental improvement that fits into existing IAM Identity Center workflows. Because configuration is API-only and details are sparse, start small, monitor impact, and build automation to manage policy changes at scale.
Sources
AWS IAM Identity Center now supports network access controls for Identity Store
Source (AWS What's New): AWS IAM Identity Center now supports network access controls for Identity Store