Joining an AWS Managed Microsoft AD to an existing domain

0

Hi,

Im new to AWS MM AD. We have an amazon direct connect to connect our on-premise and AWS VPCs. I have a few questions.

can we create an AWS managed microsoft AD that has the same domain name as our existing?

can we create an aws manage microsoft AD and join it to our existing microsoft AD?

can we create an aws managed microsoft AD in the same VPC as our on premise EC2 instance of Microsoft AD?

In managing aws managed microsoft AD do we need a jump machine to do that?

asked 3 years ago967 views
4 Answers
0
Accepted Answer

Q) You mean to say its another domain from my existing on-prem?
Ans: If you are asking this for trust creation then the answer is yes, create a trust between AWS Managed AD and your on-prem AD but on-prem AD and AWS AD should have different names.

Q) By the way is autojoin a feature only for AWS managed AD? If I have an EC2 instance with AD role inside can it be able to use autojoin to domain feature?
Ans: If you want the feature of autojoin and use services like WorkDocs, WorkSpaces for on-prem AD(AD on EC2) please create an AD connector for this AD and you will have all these features. Please refer the below mentioned articles for details and pricing
https://docs.aws.amazon.com/directoryservice/latest/admin-guide/directory_ad_connector.html
https://aws.amazon.com/directoryservice/other-directories-pricing/

AWS
Robin-P
answered 3 years ago
profile picture
EXPERT
reviewed 10 months ago
0

can we create an AWS managed microsoft AD that has the same domain name as our existing?
can we create an aws manage microsoft AD and join it to our existing microsoft AD?

No, AWS Manage Microsoft AD is provided as a single domain AD forest that, as the name implies, is fully managed by AWS. We retain Domain Admin rights and do not grant permissions that would allow you create your own domain controllers. Instead we encourage you to create a Trust between the managed domain and your on premise domain. In order to create a trust the domain names can not conflict. Therefore you should not create an AWS Managed Microsoft AD domain that has the same name as your existing domain.

can we create an aws managed microsoft AD in the same VPC as our on premise EC2 instance of Microsoft AD?

Yes

In managing aws managed microsoft AD do we need a jump machine to do that?

The most common solution is to join a Windows computer to the domain and use the RSAT tools as you would your on premise domain. Or if you have a Trust setup you could even manage both domains from one computer.

profile pictureAWS
answered 3 years ago
0

You mean to say its another domain from my existing on-prem?

By the way is autojoin a feature only for AWS managed AD? If I have an EC2 instance with AD role inside can it be able to use autojoin to domain feature?

answered 3 years ago
0

So in an AWS managed MS AD we do not have the enterprise or domain admin rights? Can we even create a user that will be a member of domain admin?

answered 3 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions