AWS Directory Service
- What it is
- Managed Microsoft Active Directory and AD connectivity options in AWS.
- The three options
- AWS Managed Microsoft AD — a real Microsoft AD running in AWS. Supports trusts with on-premises AD, Group Policy, and AD-aware apps (SharePoint, SQL Server, Amazon FSx for Windows).
- AD Connector — a proxy. Redirects authentication requests to your existing on-premises AD; stores nothing in the cloud.
- Simple AD — a small, low-cost Samba-based directory for basic needs. No trusts, limited features.
- Use cases
- Joining EC2 Windows instances to a domain, Amazon WorkSpaces user directories, existing AD-dependent applications.
- Not to be confused with
- AWS IAM Identity Center — SSO front end; it can use Directory Service as its identity source.