Joining an AWS Managed Microsoft AD to an existing domain

0

Hi,

Im new to AWS MM AD. We have an amazon direct connect to connect our on-premise and AWS VPCs. I have a few questions.

can we create an AWS managed microsoft AD that has the same domain name as our existing?

can we create an aws manage microsoft AD and join it to our existing microsoft AD?

can we create an aws managed microsoft AD in the same VPC as our on premise EC2 instance of Microsoft AD?

In managing aws managed microsoft AD do we need a jump machine to do that?

질문됨 3년 전998회 조회
4개 답변
0
수락된 답변

Q) You mean to say its another domain from my existing on-prem?
Ans: If you are asking this for trust creation then the answer is yes, create a trust between AWS Managed AD and your on-prem AD but on-prem AD and AWS AD should have different names.

Q) By the way is autojoin a feature only for AWS managed AD? If I have an EC2 instance with AD role inside can it be able to use autojoin to domain feature?
Ans: If you want the feature of autojoin and use services like WorkDocs, WorkSpaces for on-prem AD(AD on EC2) please create an AD connector for this AD and you will have all these features. Please refer the below mentioned articles for details and pricing
https://docs.aws.amazon.com/directoryservice/latest/admin-guide/directory_ad_connector.html
https://aws.amazon.com/directoryservice/other-directories-pricing/

AWS
Robin-P
답변함 3년 전
profile picture
전문가
검토됨 일 년 전
0

can we create an AWS managed microsoft AD that has the same domain name as our existing?
can we create an aws manage microsoft AD and join it to our existing microsoft AD?

No, AWS Manage Microsoft AD is provided as a single domain AD forest that, as the name implies, is fully managed by AWS. We retain Domain Admin rights and do not grant permissions that would allow you create your own domain controllers. Instead we encourage you to create a Trust between the managed domain and your on premise domain. In order to create a trust the domain names can not conflict. Therefore you should not create an AWS Managed Microsoft AD domain that has the same name as your existing domain.

can we create an aws managed microsoft AD in the same VPC as our on premise EC2 instance of Microsoft AD?

Yes

In managing aws managed microsoft AD do we need a jump machine to do that?

The most common solution is to join a Windows computer to the domain and use the RSAT tools as you would your on premise domain. Or if you have a Trust setup you could even manage both domains from one computer.

profile pictureAWS
답변함 3년 전
0

You mean to say its another domain from my existing on-prem?

By the way is autojoin a feature only for AWS managed AD? If I have an EC2 instance with AD role inside can it be able to use autojoin to domain feature?

답변함 3년 전
0

So in an AWS managed MS AD we do not have the enterprise or domain admin rights? Can we even create a user that will be a member of domain admin?

답변함 3년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인