- Added optional network access controls for Identity Store and SCIM APIs, allowing restrictions by VPC endpoints, source VPCs, or IP ranges.
- Supports per‑API configuration, e.g., VPC‑only for Identity Store API while permitting SCIM requests from external provider IP ranges.
- Controls are disabled by default, AWS service calls are exempt, and configuration is done via the Identity Store API using SDKs or CLI.