AWS Launches New Verified Access Service to Replace VPN

Amazon AWS

Amazon has announced the general availability of its AWS Verified Access service. The service enables IT admins to provide secure access to enterprise applications without using a Virtual Private Network (VPN).

AWS Verified Access originally launched in public preview in November at AWS re:Invent 2022.
The service allows customers to create, configure and manage a collection of policies and criteria for accessing private applications. The feature provides an additional layer of security to prevent users from sharing corporate data through insecure VPN servers.

“Built using AWS Zero Trust principles, customers can use Verified Access to reduce the risks associated with remote connectivity. IT administrators and developers can define fine-grain access per application using real-time contextual signals, including identity and device posture. Verified Access also simplifies security operations. Customers can manage policies for each application all in one place,” Amazon explained.

AWS Launches New Verified Access Service to Replace VPN

Benefits of Verified Access

Amazon highlighted several advantages of its AWS Verified Access service, including security posture improvement. It evaluates each application access request to grant access to users that meet specific security requirements. AWS Verified Access also integrates with identity and device management services to maintain access logs. It should make it easier for administrators to troubleshoot issues.

AWS Verified Access gets two new features

Amazon has also added two new security features to AWS Verified Access. The service is getting a new AWS Web Application Firewall (WAF) integration to block application-layer attacks (such as SQL injection) targeting web applications. It helps to protect various resources such as AWS App Runner service, Amazon CloudFront distribution, and Application Load Balancer.

Additionally, AWS Verified Access supports passing signed identity context (email, username, and other attributes) to application endpoints. It’s possible to use the context to personalize applications.

AWS Verified Access is currently available for all enterprise customers, and you can get started today on the official website. Amazon says that users will be charged for each application on Verified Access, and the amount of data processed by the service.