AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityHard

A global manufacturing company has multiple production facilities worldwide, each with its own on-premises Active Directory (AD) domain. The company is migrating several applications to AWS and requires these applications to authenticate users and resources against the on-premises ADs. The solution must ensure high availability, minimize latency for authentication requests, and simplify management across multiple distinct AD forests without establishing complex two-way trusts between all forests. Which AWS service should be used to extend Active Directory to AWS?

  1. AAWS Directory Service for Microsoft AD (Enterprise Edition) in a central VPC, connected to all on-premises ADs via a Direct Connect Gateway, and establish two-way trusts.
  2. BAWS Directory Service for Microsoft AD (Enterprise Edition) with AD Connector in each VPC
  3. CAWS Directory Service AD Connector deployed in each region and configured to connect to on-premises Active Directory domains via Direct Connect
  4. DAWS Directory Service for Microsoft AD (Enterprise Edition) in each region and establish one-way trusts with on-premises ADs
Show answer & explanation

Correct answer: C. AWS Directory Service AD Connector deployed in each region and configured to connect to on-premises Active Directory domains via Direct Connect

AD Connector acts as a proxy for your on-premises Active Directory, allowing AWS applications to authenticate without synchronizing or replicating AD data to AWS. Deploying AD Connector in each region and connecting via Direct Connect minimizes latency and provides high availability for authentication requests, simplifying management by avoiding complex trust relationships across multiple distinct on-premises AD forests.

Why the other options are wrong

  • A. Establishing a centralized AWS Managed AD and then two-way trusts with *all* on-premises ADs from different forests would introduce significant complexity in trust management and potentially latency if the central AD is far from some facilities. AD Connector avoids this complexity.
  • B. Deploying AWS Directory Service for Microsoft AD (Enterprise Edition) implies running a managed AD in AWS. While it can be used, the requirement to authenticate against *on-premises ADs* without complex trusts suggests a proxy approach rather than replicating or establishing trusts with multiple distinct forests.
  • D. Establishing one-way trusts from AWS Managed AD to multiple on-premises ADs would still require managing those trusts and potentially synchronizing some data, adding complexity. The question implies distinct AD forests where a proxy might be simpler.

AWS Directory Service AD Connector

A proxy service that allows AWS applications to use an existing on-premises Microsoft Active Directory without deploying a managed AD in AWS or establishing complex trusts.

  • Acts as a gateway to forward authentication requests to on-premises AD.
  • No synchronization or replication of AD data to AWS is required.
  • Simplifies hybrid AD integration, especially with multiple distinct on-premises AD forests.
  • Requires network connectivity (VPN or Direct Connect) to on-premises AD.

Memory trick: AD Connector is the direct, trusting bridge to multiple on-prem forests, no copies needed.

More Design Solutions for Organizational Complexity questions