With IAM Identity Center and Device Trust Provider - After Initial Request
Publication date: February 22, 2023 (Diagram history)
This flow shows how AWS Verified Access handles subsequent requests when the application domain is already in the browser extension's trusted domain list. The browser extension automatically includes the device information cookie with each request.
AWS Verified Access with IAM Identity Center and device trust - subsequent request flow
The following steps describe the request verification flow:
-
The application domain is in the browser extension's allow list. The browser extension sets the device information cookie.
-
The user sends the initial request to the AWS Verified Access endpoint. The identity cookie and device information cookie are included with the request to the application domain.
-
AWS Verified Access receives the request with the user identity cookie and device information cookie. For each request, it validates the user request against the policy using both the user identity and device posture.
-
AWS Verified Access proxies validated requests to application endpoints in the customer Amazon VPC.
Note
The identity cookie has a lifetime associated with it. When that lifetime expires, the user must re-authenticate with IAM Identity Center. The local device agent continuously gathers device posture information for each request.
Further reading
For additional information, see the following resources:
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Reference architecture diagram first published. | February 22, 2023 | |
Reference architecture diagram first published. | February 22, 2023 | |
Reference architecture diagram first published. | February 22, 2023 | |
Initial publication | Reference architecture diagram first published. | February 22, 2023 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.