AWS IAM Identity Center Gets Network Access Controls for Identity Store
AWS IAM Identity Center now lets you lock down access to your Identity Store API and SCIM API by restricting requests to specific VPC endpoints, source VPCs, or IP ranges. This means your user provisioning workflows and external identity providers can only talk to your identity data from networks you explicitly allow—perfect for tightening security in multi-account setups.
source: [aws/whats-new]