Yes. isolated subnets have no access IG or NAT so no direct access. If you have something inside your VPN (bastion, lambda, LB, anything) you can set up NACLs and SGs to allow access between that thing and the isolated subnets, then control your isolated resources that way.