Amazon OpenSearch UI supports network access controls
Amazon OpenSearch Service now allows network access controls for its UI applications, enabling users to restrict access to approved networks via IAM condition keys. This feature enhances security by establishing a consistent data perimeter and preventing off-network access before authentication. It is available in all AWS Regions where OpenSearch UI is offered and is primarily targeted at engineers and architects managing AWS environments.
- →Network access controls for OpenSearch UI
- →Block off-network access before authentication
- →Consistent data perimeter enforcement
- →Availability and further information
Features (2) ›
- Network access controls for OpenSearch UI
Amazon OpenSearch Service now supports network access controls for OpenSearch UI applications. This allows restriction of access to approved networks using existing IAM condition keys like aws:SourceVpce, aws:SourceVpc, and aws:SourceIp.
- Block off-network access before authentication
Resource control policies (RCPs) can block off-network users before they authenticate, preventing access to the login page from outside the corporate network or VPC.
Enhancements (1) ›
- Consistent data perimeter enforcement
The new controls help establish a consistent data perimeter across AWS environments by enforcing network restrictions. This can be done at the identity, VPC endpoint, or resource control policy (RCP) level.
Notes (1) ›
- Availability and further information
Network access controls are available in all AWS Regions where OpenSearch UI is available. More details can be found in the Amazon OpenSearch Service Developer Guide.
https://aws.amazon.com/about-aws/whats-new/2026/08/opensearch-ui-network-access-control
Related releases
- Amazon S3 enhances access denied errors with specific policy ARNs AWS What's New ·
- AWS IAM Role Manager Automates Service Role Setup AWS What's New ·
- AWS IAM Role Manager Streamlines Identity and Access Management Setup AWS Security Blog ·
- Terraform AWS Provider v6.59.0 Adds New Data Sources and Resources Terraform AWS Provider Releases ·
- AWS IAM simplifies role assignment for workforce users with account access manager AWS What's New ·
- Amazon Bedrock expands IAM principal cost allocation for mantle endpoint AWS What's New ·