Active Directory allows developers to integrate Amazon WorkSpaces instances with a local data center for a more...
consistent end-user experience. And integrating on-premises and cloud environments gives WorkSpaces instances added flexibility.
A Microsoft Active Directory (Microsoft AD) connection enables end users to access both WorkSpaces and company resources via existing credentials. This single sign-on creates a more seamless end-user experience and often cuts down on IT admin support for lost or forgotten passwords. Integration with Amazon Virtual Private Cloud or AWS Direct Connect is also secured.
There are two ways to establish a Microsoft AD connection. Administrators can set up an inter-forest trust relationship with the AWS Directory Service for the AD domain controller. This approach works best when an on-premises environment uses multiple AD domains. It requires only a single-trust relationship between on-premises AD and the Microsoft AD domain controller. Administrators can then assign Amazon WorkSpaces to end users in any on-premises domain. Microsoft AD automatically identifies and directs authentication requests to the proper domain controller.
Administrators also can use Active Directory Connector to proxy AD authentication requests. This requires a separate AD Connector for each on-premises domain where users receive WorkSpaces instances. But the process is often easier when the on-premises environment uses only one domain, which is preferable for testing.
Connecting Amazon WorkSpaces to on-premises domains enables end users to recover lost passwords using the same protocol or process as they would in traditional on-premises scenarios. For example, if password recovery or resets are handled through the help desk, integrated WorkSpaces users will also direct users to those same resources. AWS documentation provides more information about establishing, maintaining and troubleshooting a Microsoft AD connection with WorkSpaces.
Amazon WorkSpaces also connects with different applications that run in Elastic Compute Cloud (EC2) instances in either conventional or Amazon Virtual Private Cloud environments. Administrators need to configure the proper routing tables, security groups and network access control lists to access certain EC2 instances to facilitate a Microsoft AD connection.
Learn how VDI works on AWS
What other cloud directory services does AWS support?
Know these five Amazon WorkSpaces management tasks
Dig Deeper on Amazon WorkSpaces and other DaaS options
Related Q&A from Stephen J. Bigelow
Full virtualization and paravirtualization both enable hardware resource abstraction, but the two technologies differ when it comes to isolation ... Continue Reading
Organizations can cap their hyper-converged infrastructure costs when they deploy the Azure Stack HCI platform, but once they plug into the cloud, ... Continue Reading
You can implement ESXi on ARM -- or other RISC processors -- in micro and nano data centers. A nano data center is more specialized but also more ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.