Extend your data perimeter to the AWS Management Console with Private Access
Security Blog
This article announces that AWS Management Console Private Access is now generally available with support for VPCs without internet connectivity, allowing organizations to route all console traffic through PrivateLink endpoints.
- Route console traffic, authentication flows, static assets, and service API calls entirely through VPC endpoints with no internet gateway required
- Combine VPC endpoint policies with Sign-In resource control policies to restrict console access by network and organization
- Prevent data exfiltration by blocking console access from personal accounts and accounts outside your organization
- Deploy incrementally starting with a single Region and organizational unit, validating each step before expanding
- Create three interface VPC endpoints (console, signin, console-static) and configure private DNS for domain resolution
- Apply endpoint policies using aws:PrincipalOrgID and aws:ResourceOrgID conditions to enforce data perimeter controls
- Add service-specific VPC endpoints (e.g., KMS) so console API calls route privately through your network
Organizations in regulated industries can now enforce complete network isolation for AWS Management Console access while maintaining operational convenience through layered identity, resource, and network controls.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2024
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.