All Services

Networking & CDN

AWS Verified Access

AWS Verified Access provides policy-controlled access to private applications without a traditional VPN by evaluating identity and optional device trust on each request.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Verified Access.

AWS Verified Access pricing and cost programs

Pricing model: Endpoint and data processing usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Verified Access endpoints · Data processed

Programs and modes: Hourly endpoint charge · Per-GB processing

Verified Access is billed by configured endpoints and traffic processed.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS Verified Access?

  • Evaluates every application request against identity, device, and policy context instead of granting broad network access after a VPN connection.
  • Provides application-level access with AWS and third-party trust providers, improving user experience for supported private web applications.
  • Records access attempts centrally to support troubleshooting, incident response, and audits.

How to implement AWS Verified Access

  1. Configure an identity trust provider and, where needed, a device trust provider, then create a Verified Access instance.
  2. Create a group for applications with similar security requirements, add an endpoint for the application, and configure its domain, certificate, DNS, subnets, and security groups.
  3. Add deny-by-default group and endpoint policies, test allowed and denied paths, and deliver access and trust-provider logs to an approved destination.

AWS Verified Access best practices

  • Group endpoints by common security requirements and keep application-specific exceptions in endpoint policies rather than broadening the shared policy.
  • Use federated identities, least-privilege administration, short and testable policy expressions, and device context for higher-risk applications.
  • Restrict application security groups to the Verified Access endpoint, protect public entry points as appropriate, and continuously review access logs and denied requests.

AWS Verified Access use cases and server impact

  • Workforce access to private web applications
  • Replacing application-level VPN access
  • Context-aware contractor and partner access

Replaces VPN gateways and broad network tunnels for supported application access, but it does not replace the application, identity provider, or endpoint infrastructure.

Official implementation resources

Commonly paired AWS services