9 November,16 at 02:41 PM
Applies to: All version of Centrify DirectControl on all platforms
Question:
Can we manage Active Directory from Amazon Web Services (AWS) with one-way trust relationship?
Answer:
This setup is not recommended by Centrify, especially not for any financial institutions. As there are lots of security concerns and problem when uses AWS Directory Services.
AWS Directory service provides the user domain in an OU. We can only be the AWS user, but NOT domain administrator. We are delegated the permission to the OU where all users/groups and AD objects are supposed to live in.
We cannot RDP into Domain Controller. We have to set up another W2012R2 server with Remote Server Admin Tools to access the DC.
Domain admin group members are, presumably AWS users, so, the domain is completely opened to others that are not part of the company.
Not all AWS region support Directory Service.