Joining an AWS Managed Microsoft AD to an existing domain

0

Hi,

Im new to AWS MM AD. We have an amazon direct connect to connect our on-premise and AWS VPCs. I have a few questions.

can we create an AWS managed microsoft AD that has the same domain name as our existing?

can we create an aws manage microsoft AD and join it to our existing microsoft AD?

can we create an aws managed microsoft AD in the same VPC as our on premise EC2 instance of Microsoft AD?

In managing aws managed microsoft AD do we need a jump machine to do that?

demandé il y a 3 ans996 vues
4 réponses
0
Réponse acceptée

Q) You mean to say its another domain from my existing on-prem?
Ans: If you are asking this for trust creation then the answer is yes, create a trust between AWS Managed AD and your on-prem AD but on-prem AD and AWS AD should have different names.

Q) By the way is autojoin a feature only for AWS managed AD? If I have an EC2 instance with AD role inside can it be able to use autojoin to domain feature?
Ans: If you want the feature of autojoin and use services like WorkDocs, WorkSpaces for on-prem AD(AD on EC2) please create an AD connector for this AD and you will have all these features. Please refer the below mentioned articles for details and pricing
https://docs.aws.amazon.com/directoryservice/latest/admin-guide/directory_ad_connector.html
https://aws.amazon.com/directoryservice/other-directories-pricing/

AWS
Robin-P
répondu il y a 3 ans
profile picture
EXPERT
vérifié il y a 10 mois
0

can we create an AWS managed microsoft AD that has the same domain name as our existing?
can we create an aws manage microsoft AD and join it to our existing microsoft AD?

No, AWS Manage Microsoft AD is provided as a single domain AD forest that, as the name implies, is fully managed by AWS. We retain Domain Admin rights and do not grant permissions that would allow you create your own domain controllers. Instead we encourage you to create a Trust between the managed domain and your on premise domain. In order to create a trust the domain names can not conflict. Therefore you should not create an AWS Managed Microsoft AD domain that has the same name as your existing domain.

can we create an aws managed microsoft AD in the same VPC as our on premise EC2 instance of Microsoft AD?

Yes

In managing aws managed microsoft AD do we need a jump machine to do that?

The most common solution is to join a Windows computer to the domain and use the RSAT tools as you would your on premise domain. Or if you have a Trust setup you could even manage both domains from one computer.

profile pictureAWS
répondu il y a 3 ans
0

You mean to say its another domain from my existing on-prem?

By the way is autojoin a feature only for AWS managed AD? If I have an EC2 instance with AD role inside can it be able to use autojoin to domain feature?

répondu il y a 3 ans
0

So in an AWS managed MS AD we do not have the enterprise or domain admin rights? Can we even create a user that will be a member of domain admin?

répondu il y a 3 ans

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.

Instructions pour répondre aux questions