The right identity.
The right network.

AccessGuard keeps your approved IP ranges in sync with AWS Service Control Policies. Add a network boundary to AWS API access across the member accounts you choose.

Same credentials. Different source. Example
Corporate VPN203.0.113.24
Valid credentials
AWS API requestec2:DescribeInstances
AWS evaluates the source restriction
AccessGuard policySCP
Approved range203.0.113.0/24
Source matchOn your allowlist
Passes the source restriction

IAM and other AWS policies still determine access.

Add a boundary around cloud access

A valid key can still come
from the wrong place.

Make approved public egress part
of your AWS access policy.

Limit exposed-key use

Help contain credential misuse by denying covered requests from outside your approved network ranges.

A second condition for access

Use the egress you trust

Make corporate VPNs, secure proxies, and other controlled public exits the expected path for AWS administration.

Your network choices, reflected in AWS

Keep accounts aligned

Apply a shared source policy to member accounts through AWS Organizations, with an approved list maintained in FraudGuard.

Consistent policy across your target scope

From your allowlist to AWS policy

You define trust.
AccessGuard keeps it in sync.

Read the deployment guide
  1. 01 / DEFINE

    Choose approved networks.

    Maintain your trusted public IP ranges in your FraudGuard allowlist. Your team decides which sources belong there.

    Customer-managed trust
  2. 02 / SYNC

    Keep the policy current.

    A scheduled Lambda in your AWS environment retrieves the list and updates the Service Control Policy for your target scope.

    FraudGuard → Lambda → AWS Organizations
  3. 03 / ENFORCE

    Let AWS apply the boundary.

    Covered requests must meet the source policy or a configured exception, alongside the permissions already required by AWS.

    Evaluated by AWS on the request

Your AWS account stays in control. FraudGuard supplies the allowlist; the sync function and enforcement policy run in your environment.

A rollout you can review

Review the policy.
Then enforce it.

Select dry-run mode to inspect the generated policy without changing AWS Organizations. Validate a test OU, confirm critical access paths, then enable enforcement for the scope you’ve reviewed.

Plan emergency access and recovery before expanding to more accounts.

A strong fit when you have

AWS Organizations

All features and SCP support enabled, with deployment from the management account.

Stable public egress

Known VPN, proxy, or other approved IP ranges for your people and automation.

A defined access model

Reviewed service calls, exceptions, and a dependable recovery path.

We’ll help you assess fit before production enforcement.

A few useful details

Before you set
the boundary.

Explore the deployment guide
Does AccessGuard replace IAM or MFA?

No. It adds a source-network restriction to your existing AWS permissions. An approved IP does not grant access or prove that a request is legitimate. Keep IAM, MFA, least privilege, and your other identity controls in place.

Which AWS accounts does it cover?

The policy applies to member accounts under the selected organizational unit or organization root. SCPs do not restrict management-account identities or service-linked roles, and other AWS-documented exceptions apply. Scope and test the policy for your environment.

What about automation and VPC endpoints?

Include approved public egress for automation and review AWS service calls during deployment. VPC endpoint requests do not carry the same public source-IP context. Those paths need separate review and testing; see the deployment guide for details.

How quickly do allowlist changes reach AWS?

AccessGuard syncs on a configurable schedule; the template uses five minutes by default. Changes take effect after a successful policy update and AWS propagation. If the allowlist fetch fails, the existing policy stays in place.

Can we preview it before turning on enforcement?

Yes. Select dry-run mode to log the generated policy without creating, updating, or attaching it. Test with a small OU and review approved, unapproved, and exception access paths before enabling enforcement.

Which plans include AccessGuard?

AccessGuard is available on Professional and above. Compare plans and talk to us about deployment to confirm fit for your AWS organization. AWS usage is billed separately by AWS.

Make network trust part of access

Bring your approved networks
into your AWS policy.

Tell us about your egress, accounts, and access paths.
We’ll help you scope the next step.