Amazon iconAmazonSep 23, 2026 ~7 min source read

Configure domain-level VPC networking in Amazon SageMaker Unified Studio

Set a single, audited VPC at the SageMaker Unified Studio domain level so every new project inherits consistent private networking. Learn the configuration, prerequisites, how to update existing projects, and how to validate connectivity.

Configure domain-level VPC networking in Amazon SageMaker Unified Studio

Share this story

Send the public story page.

Useful takeaways from this story.

Configure a single domain-level VPC so all new SageMaker Unified Studio projects automatically inherit consistent private subnets, security groups, and VPC endpoints.

Domain VPC requirements include at least two private subnets in different Availability Zones, DNS enabled, VPC endpoints with private DNS, and S3 gateway route table associations for the selected private subnets.

Grant domain administrators the SageMakerStudioAdminIAMConsolePolicy (or equivalent) and ensure the domain and VPC are in the same AWS Region.

# Why set VPC networking at the domain level Configuring VPC networking per project leads to inconsistent subnet choices, missing endpoints, connectivity failures that are hard to troubleshoot, and an environment that's difficult to audit. Domain-level VPC networking centralizes network settings so new projects get the right private networking automatically.

# What this approach gives you

  • Configure once, apply consistently to new projects. New projects inherit subnets, security groups, and endpoints without network-team intervention.
  • Simpler auditing: one VPC to review with VPC Flow Logs and CloudTrail events.
  • Reduced operational overhead: project teams can start work without individual networking requests.

# Core requirements and recommended minimums

  • VPC in the same AWS Region as the SageMaker Unified Studio domain.
  • At least two private subnets in different Availability Zones for multi-AZ resilience.
  • DNS hostnames and DNS support enabled for the VPC.
  • VPC endpoints for AWS services your projects access (for example, S3, AWS Glue, SageMaker AI) and Private DNS enabled on interface endpoints so service DNS resolves to private IPs.
  • The domain administrator must have the SageMakerStudioAdminIAMConsolePolicy managed policy or equivalent permissions (including ec2:Describe, ec2:CreateSecurityGroup, and datazone: where applicable).

# How the solution is organized (high level)

  1. Configure the domain-level VPC in the SageMaker Unified Studio domain settings, selecting the VPC, private subnets across AZs, and a security group.
  2. Ensure VPC endpoints and Private DNS are in place so compute in private subnets can reach required AWS services without internet access.

# Validation and auditing

  • Turn on VPC Flow Logs and review CloudTrail events to audit network activity and configuration changes.

# Practical next steps for administrators

  • Confirm the VPC meets the subnet, DNS, and IP capacity guidance for your expected users and compute footprint.
  • Create or verify required VPC endpoints and enable Private DNS on interface endpoints.
  • Attach the SageMakerStudioAdminIAMConsolePolicy to the domain administrator role or ensure equivalent permissions.
  • Configure domain-level VPC networking in the SageMaker Unified Studio domain settings and then test a new project to verify inheritance and connectivity.

# When to update vs. recreate existing projects

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app