With IAM Identity Center and Device Trust Provider - Initial Request
Publication date: February 22, 2023 (Diagram history)
This flow shows how AWS Verified Access handles an initial request when both IAM Identity Center and a device trust provider are configured. The browser extension detects redirects and provides device information cookies for combined identity and device posture validation.
AWS Verified Access with IAM Identity Center and device trust - initial request flow
The following steps describe the request verification flow:
-
Steps 1 through 5 are the same as the IAM Identity Center initial request flow.
-
The browser extension detects the 302 redirect but does not identify the application domain as an AWS Verified Access domain. No device information cookie is added.
-
AWS Verified Access expects device information but does not receive it. It redirects the user to the device validation domain. AWS Verified Access repeats the authentication steps, but IAM Identity Center bypasses sign-in because cookies from the previous sign-in exist.
-
The device validation domain sends a 302 redirect. This tells the browser extension to pass the device information cookie to the application domain.
-
The browser extension extracts the application domain from the redirect and adds it to the cache of trusted AWS Verified Access domains. It sets the device information cookie on the application domain.
-
The browser extension allows the redirect to continue.
-
AWS Verified Access receives the request with the user identity cookie and device information cookie. For each request, it validates the user request against the policy using both the user identity and device posture.
-
AWS Verified Access proxies validated requests to application endpoints in the customer Amazon VPC.
Note
The local device agent continuously gathers device posture information. The browser extension transmits up-to-date information for each request to an AWS Verified Access endpoint.
Further reading
For additional information, see the following resources:
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Reference architecture diagram first published. | February 22, 2023 | |
Reference architecture diagram first published. | February 22, 2023 | |
Initial publication | Reference architecture diagram first published. | February 22, 2023 |
Reference architecture diagram first published. | February 22, 2023 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.