AWS made Console Private Access generally available on August 28 for VPCs with no internet path, moving AWS Management Console sign-in, page assets, and supported console APIs onto PrivateLink. The change extends the private route operators already used for sign-in and service APIs to the console itself.
The mechanism is simple but unforgiving: if Private DNS, endpoint security groups, or sign-in resource control policies are wrong, valid credentials can be blocked before the console loads. AWS also says only a subset of service consoles is supported, and unsupported consoles will not load in a no-internet VPC.
For regulated or isolated networks, the exposure now sits in the private access design rather than the public perimeter. The lasting question is which accounts are trusted to reach the console, and whether a break-glass path exists before a policy mistake turns private access into an org-wide outage.