Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-7782: Can we manage AD from Amazon Web Services with one-way trust?

Authentication Service ,  

9 November,16 at 02:41 PM

Applies to: All version of Centrify DirectControl on all platforms


Can we manage Active Directory from Amazon Web Services (AWS) with one-way trust relationship?


This setup is not recommended by Centrify, especially not for any financial institutions. As there are lots of security concerns and problem when uses AWS Directory Services.

  1. AWS Directory service provides the user domain in an OU. We can only be the AWS user, but NOT domain administrator. We are delegated the permission to the OU where all users/groups and AD objects are supposed to live in.

  2. We cannot RDP into Domain Controller. We have to set up another W2012R2 server with Remote Server Admin Tools to access the DC.

  3. Domain admin group members are, presumably AWS users, so, the domain is completely opened to others that are not part of the company.

  4. Not all AWS region support Directory Service.