Amazon Web Services (AWS) introduced its VPN-less, zero-trust network access (ZTNA)-like secure connectivity service, dubbed Verified Access, during its re:Invent 2022 event. The service is designed to deliver customers secure access to corporate applications running on AWS without the need for a VPN while enforcing zero-trust principles.

The AWS Verified Access aims to secure remote/hybrid workforces, as traditionally, organizations are using VPNs to secure remote access to applications, and Amazon internally adopted a VPN-less strategy a few years ago, according to AWS’ blog post.

“Your workforce is not required to use a VPN client anymore. A simple browser plugin is enough to securely grant access when the user and the device are identified and verified,” AWS’ Sébastien Stormacq noted, adding the service now supports Chrome and Firefox web browsers.

Additionally, Stormacq highlighted that Verified Access is built on the vendor’s zero-trust security principles. AWS defines zero trust as a security model based on the idea that data access should not be solely made based on network location but requires users and systems to prove their identities and trustworthiness while enforcing fine-grained, identity-based authorization rules before granting access to data, applications, and other systems.

To that point, the new Verified Access creates a set of fine-grained policies to define the conditions for remote application access. Meanwhile, the service evaluates every application's access, and only when users and their devices meet those security requirements can they have access. It also allows users to define their own access policy for each application, according to AWS.

The service also enables users to retain their existing identity provider and device management system. For example, Rapid7 integrates its Insight platform with AWS Verified Access, which allows the security vendor’s customers to ingest logs from the Verified Access, so they can have visibility into who is accessing private applications so that any suspicious activity can be investigated, according to Rapid7.

The Verified Access now is in public preview in 10 AWS regions, and its pricing is based on the usage.