Networking & CDN
AWS Verified Access
AWS Verified Access provides policy-controlled access to private applications without a traditional VPN by evaluating identity and optional device trust on each request.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Verified Access.
AWS Verified Access pricing and cost programs
Pricing model: Endpoint and data processing usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Verified Access endpoints · Data processed
Programs and modes: Hourly endpoint charge · Per-GB processing
Verified Access is billed by configured endpoints and traffic processed.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Verified Access?
- Evaluates every application request against identity, device, and policy context instead of granting broad network access after a VPN connection.
- Provides application-level access with AWS and third-party trust providers, improving user experience for supported private web applications.
- Records access attempts centrally to support troubleshooting, incident response, and audits.
How to implement AWS Verified Access
- Configure an identity trust provider and, where needed, a device trust provider, then create a Verified Access instance.
- Create a group for applications with similar security requirements, add an endpoint for the application, and configure its domain, certificate, DNS, subnets, and security groups.
- Add deny-by-default group and endpoint policies, test allowed and denied paths, and deliver access and trust-provider logs to an approved destination.
AWS Verified Access best practices
- Group endpoints by common security requirements and keep application-specific exceptions in endpoint policies rather than broadening the shared policy.
- Use federated identities, least-privilege administration, short and testable policy expressions, and device context for higher-risk applications.
- Restrict application security groups to the Verified Access endpoint, protect public entry points as appropriate, and continuously review access logs and denied requests.
AWS Verified Access use cases and server impact
- Workforce access to private web applications
- Replacing application-level VPN access
- Context-aware contractor and partner access
Replaces VPN gateways and broad network tunnels for supported application access, but it does not replace the application, identity provider, or endpoint infrastructure.
Official implementation resources
Commonly paired AWS services
- AWS IAM Identity Center — Workforce identity access
- Elastic Load Balancing — Load balancing
- AWS Certificate Manager — TLS certificate management
- Amazon Route 53 — DNS & routing
- AWS WAF — Web app firewall
- Amazon Virtual Private Cloud — Isolated virtual network
- Amazon CloudWatch — Metrics & logs
- Amazon Simple Storage Service — Object storage