AWS Certified Solutions Architect – ProfessionalAccelerate Workload Migration and ModernizationMedium
A large enterprise is migrating a complex, multi-tier application to AWS. The application currently relies on a Windows Server Active Directory for user authentication and authorization, and it's critical to maintain a seamless user experience during and after the migration. The enterprise wants to minimize operational overhead for directory services on AWS. Which of the following strategies provides the MOST seamless integration with existing Active Directory and minimizes management burden?
- ASet up a new AWS Managed Microsoft AD in a dedicated VPC and use AWS Directory Service for Active Directory Connector to connect to the on-premises Active Directory.
- BMigrate all users and groups from the on-premises Active Directory to AWS Identity and Access Management (IAM) and configure SAML federation for application access.
- CImplement AWS Directory Service for Microsoft Active Directory (Managed AD) and create a two-way forest trust with the on-premises Active Directory.
- DDeploy a new set of Windows Server EC2 instances on AWS, promote them to domain controllers, and establish a one-way forest trust with the on-premises Active Directory.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement AWS Directory Service for Microsoft Active Directory (Managed AD) and create a two-way forest trust with the on-premises Active Directory.
AWS Managed Microsoft AD provides a fully managed, highly available Active Directory service. Establishing a two-way forest trust with the on-premises AD allows seamless synchronization of users and groups, providing a single identity plane and minimizing operational overhead.
Why the other options are wrong
- A. Active Directory Connector is primarily for connecting to an on-premises AD from AWS services, not for creating a new Managed AD and then connecting, and it doesn't offer the same level of integration as a forest trust.
- B. Migrating all users to IAM and using SAML federation would require significant changes to application authentication logic and would not maintain the seamless integration with existing Active Directory group policies and user management that the question requires.
- D. Deploying EC2 instances as domain controllers increases operational overhead for patching, backups, and high availability compared to AWS Managed Microsoft AD.
AWS Managed Microsoft AD with Two-Way Trust
A fully managed AWS service that hosts Microsoft Active Directory, enabling seamless integration with on-premises AD via a two-way forest trust.
- Reduces operational burden of managing AD servers.
- Provides a single identity plane across on-premises and AWS.
- Supports standard AD features like Group Policy and DNS.
Memory trick: Managed AD, Two-Way Trust, Total Ease