An enterprise is performing a large-scale migration of legacy Windows Server applications to AWS. Many of these applications have hardcoded IP addresses or rely on specific DNS names that are currently managed by an on-premises Active Directory and DNS infrastructure. The enterprise wants to maintain these existing hostnames and IP addresses during the migration to minimize application refactoring while moving to a fully managed DNS solution in AWS. Which approach BEST facilitates this requirement?
- AUse AWS Managed Microsoft AD and configure custom DNS records in Route 53 Public Hosted Zones.
- BExtend the on-premises Active Directory to AWS EC2 and use AWS Directory Service for Microsoft Active Directory, integrated with Route 53 Resolver.
- CRe-architect applications to use dynamic DNS updates and AWS Cloud Map for service discovery.
- DMigrate Windows Servers to Amazon EC2 and configure each instance to use Amazon Route 53 for DNS resolution.
Show answer & explanationAnswer & explanation
Correct answer: B. Extend the on-premises Active Directory to AWS EC2 and use AWS Directory Service for Microsoft Active Directory, integrated with Route 53 Resolver.
Extending the on-premises Active Directory to AWS using AWS Directory Service for Microsoft Active Directory allows the enterprise to maintain existing user identities, group policies, and DNS records. Integrating this with Route 53 Resolver (specifically inbound and outbound endpoints) enables seamless resolution of both on-premises and AWS-hosted DNS records, supporting the requirement to maintain existing hostnames and IP addresses without application refactoring.
Why the other options are wrong
- A. Using Route 53 Public Hosted Zones is for public-facing DNS. For internal, private DNS resolution, especially integrated with Active Directory, Route 53 Resolver and private hosted zones are appropriate, combined with AWS Managed Microsoft AD, not public zones.
- C. Re-architecting applications to use dynamic DNS updates and Cloud Map involves significant code changes, which goes against the goal of minimizing application refactoring.
- D. Simply pointing EC2 instances to Route 53 won't resolve on-premises specific DNS names unless Route 53 is configured to forward queries, and it doesn't address Active Directory integration.
AWS Directory Service for Microsoft Active Directory (Managed AD) with Route 53 Resolver
AWS Managed Microsoft AD provides a fully managed, highly available Active Directory. Route 53 Resolver enables hybrid DNS resolution between on-premises DNS and AWS DNS, allowing resources in both environments to resolve hostnames.
- Extends or creates Active Directory in AWS.
- Manages DNS for AD-joined instances.
- Route 53 Resolver bridges on-premises and AWS DNS for seamless name resolution.
Memory trick: AD Service + Route 53 Resolver = Your old names, new cloud home, all resolved.