A global construction company has a highly customized, business-critical application that manages project bids and resource allocation. This application is tightly integrated with various on-premises systems, including an Active Directory for authentication, a proprietary budgeting tool, and a document management system (DMS). The company wants to migrate this application to AWS while maintaining seamless integration with the existing on-premises tools and minimizing changes to the application's authentication flow. They also need to ensure high availability and disaster recovery for the migrated application. Which solution best addresses these complex integration and availability requirements?
- ARe-architect the application into microservices, replace Active Directory with Amazon Cognito, and integrate with on-premises systems via API Gateway.
- BMigrate the application to AWS Lambda and Amazon DynamoDB, then use AWS Site-to-Site VPN to connect to on-premises resources.
- CPerform a 'Lift and Shift' of the application and all integrated systems to AWS Outposts for hybrid cloud operations.
- DRe-host the application to EC2 instances, migrate the database to Amazon RDS, and use AWS Directory Service for Microsoft Active Directory (Managed AD) with a trust relationship to the on-premises Active Directory.
Show answer & explanationAnswer & explanation
Correct answer: D. Re-host the application to EC2 instances, migrate the database to Amazon RDS, and use AWS Directory Service for Microsoft Active Directory (Managed AD) with a trust relationship to the on-premises Active Directory.
Re-hosting to EC2 and RDS with AWS Directory Service for Microsoft Active Directory (Managed AD) and a trust relationship allows the application to leverage existing on-premises Active Directory for authentication without changes, maintaining seamless integration. This approach provides high availability through EC2 auto-scaling and RDS multi-AZ, and enables disaster recovery within AWS.
Why the other options are wrong
- A. Re-architecting to microservices and replacing AD with Cognito would involve significant changes to the application and its authentication flow, contradicting the 'minimizing changes' requirement.
- B. Migrating to Lambda and DynamoDB is a significant re-architecture that would drastically change the application, violating the 'minimizing changes' principle for a highly customized, tightly integrated COTS application.
- C. AWS Outposts would keep the application on-premises but managed by AWS, which doesn't fully migrate to AWS or provide the same level of availability/DR as native AWS services across regions or AZs. It also doesn't explicitly address the AD integration strategy.
Hybrid Integration with AWS Managed AD
Integrating on-premises applications with AWS involves extending existing services like Active Directory to the cloud. AWS Directory Service for Microsoft Active Directory (Managed AD) can establish a trust relationship with an on-premises AD, allowing AWS resources and migrated applications to authenticate against the existing directory.
- Extends on-premises AD to AWS
- Enables seamless authentication for cloud resources
- Supports trust relationships for hybrid identity management
- Managed service, reduces operational burden
Memory trick: Managed AD: Your bridge for seamless hybrid auth.