AWS Client VPN checks device posture before and during a session, with policies in Cedar
AWS Client VPN can now check whether a connecting device meets security requirements before it gets network access, AWS announced on 5 October. Until now the service authenticated only the user, through certificates, SAML or Active Directory.
What it checks. The feature integrates with existing device-posture providers. AWS names three: CrowdStrike, Jamf and JumpCloud. Signals such as a compliance score, disk encryption status and risk level are evaluated before the connection is allowed.
How the rules are written. Requirements are expressed as policies in Cedar, the open-source authorisation language AWS already uses in other services. A Test Policy tool in Client VPN helps build and validate them before they are applied.

Not only at login. Compliance is re-evaluated during the session, and the session is disconnected automatically if the device stops complying, for example when its risk score or security settings change. A monitoring-only mode logs the posture results without disconnecting anyone, so teams can see what a policy would block before enforcing it. Posture checks run alongside the existing authorisation rules rather than replacing them.
Availability. The feature is available in every region where Client VPN runs, at no additional cost, and requires version 6.2.0 or later of the AWS VPN Client.
For teams that already run a managed-device programme, this moves Client VPN closer to the zero-trust pattern of checking the device as well as the person, without adding a separate gateway product. The monitoring mode is the sensible first step: posture policies tend to block more machines than their authors expect.