AWS Client VPN now supports device posture assessment
AWS Client VPN now enforces device security checks before granting network access, integrating with posture providers like CrowdStrike and Jamf to block non-compliant devices.
AWS Client VPN has introduced device posture assessment, enabling organizations to verify that connecting devices meet security and compliance standards before granting access to AWS resources. Previously limited to user authentication via certificates, SAML, or Active Directory, Client VPN now supports integration with third-party posture providers such as CrowdStrike, Jamf, and JumpCloud. These providers supply security signals—including compliance scores, encryption status, and risk levels—that Client VPN evaluates against defined requirements. The feature ensures only trusted devices can connect, reducing exposure to unauthorized or compromised endpoints.
To implement these checks, administrators define policies using Cedar, AWS’s policy language, which allows for granular control over device access. A new Test Policy tool assists in creating and validating these policies, ensuring they align with organizational security requirements before enforcement. Policies can be tailored to evaluate specific device attributes, such as operating system versions or installed security software, providing flexibility in compliance enforcement.
Device posture assessment operates continuously during active sessions, automatically terminating connections if a device falls out of compliance—for example, if its risk score increases or encryption settings change. This real-time enforcement helps maintain a secure network environment by preventing non-compliant devices from maintaining access. Administrators can also deploy the feature in monitoring-only mode, logging posture evaluations without disconnecting sessions to assess policy impact before full enforcement.
The feature is available in all AWS Regions where AWS Client VPN is offered, with no additional cost beyond existing Client VPN usage. It requires AWS VPN Client version 6.2.0 or later to function. Device posture assessment complements existing authorization rules, adding an additional layer of security to Client VPN deployments without disrupting current workflows.