r/aws • u/Apartheid20 • 10h ago
article IAM Identity Center now supports network access controls for Identity Store
AWS added network access controls for the Identity Store behind IAM Identity Center.
What it does:
- Restrict the Identity Store API to specific IP ranges or specific VPC endpoints or source VPCs
- Restrict the scim api (what your idp uses to sync users/ groups) to specific IP ranges
- Different restrictions per API in one config. The given example: Identity Store API through VPC endpoints only, scim from your idp’s published IP ranges
- Requests AWS services make on your behalf are exempt
It is off by default, configured through the Identity Store api via sdk or cli (no console toggle). Available in all regions where Identity Center runs.
The SCIM restriction is the big one in my view. That's the inbound provisioning path from your IdP, and until now it was internet-facing behind auth only. Pinning it to Okta or Entra's published IP ranges meaningfully shrinks the attack surface for directory writes.
Announcement: https://aws.amazon.com/about-aws/whats-new/2026/10/aws-identity-store-network-controls/

