Launch directory administration Amazon EC2 instance to your Amazon Managed Microsoft AD Active Directory
This procedure launches an Amazon EC2 Windows instance in the console using Amazon Systems Manager Automation to manage your Amazon Managed Microsoft AD Active Directory. You can also accomplish this by running the automation Amazon-CreateDSManagementInstance in the Amazon Systems Manager Automation console directly.
Prerequisites
To launch a directory administration EC2 instance from the console, you must have the following permissions enabled in your account.
ds:DescribeDirectories
ec2:AuthorizeSecurityGroupIngress
ec2:CreateSecurityGroup
ec2:CreateTags
ec2:DeleteSecurityGroup
ec2:DescribeInstances
ec2:DescribeInstanceStatus
ec2:DescribeKeyPairs
ec2:DescribeSecurityGroups
ec2:DescribeVpcs
ec2:RunInstances
ec2:TerminateInstances
iam:AddRoleToInstanceProfile
iam:AttachRolePolicy
iam:CreateInstanceProfile
iam:CreateRole
iam:DeleteInstanceProfile
iam:DeleteRole
iam:DetachRolePolicy
iam:GetInstanceProfile
iam:GetRole
iam:ListAttachedRolePolicies
iam:ListInstanceProfiles
iam:ListInstanceProfilesForRole
iam:PassRole
iam:RemoveRoleFromInstanceProfile
iam:TagInstanceProfile
iam:TagRole
ssm:CreateDocument
ssm:DeleteDocument
ssm:DescribeInstanceInformation
ssm:GetAutomationExecution
ssm:GetParameters
ssm:ListCommandInvocations
ssm:ListCommands
ssm:ListDocuments
ssm:SendCommand
ssm:StartAutomationExecution
ssm:GetDocument
To launch an EC2 instance in the console
Sign in to the Amazon Directory Service console
. Under Active Directory, choose Directories.
Choose the Directory ID of the directory where you want to launch an Active Directory management EC2 instance.
On the directory page, in the top right corner, choose Actions.
In the Actions dropdown, choose Launch directory administration EC2 instance.
On the Launch directory administration EC2 instance page, under Input parameters, complete the fields.
(Optional) Choose View Amazon CLI command to see an example that you use in the Amazon CLI to run this automation.
Choose Submit.
You're taken back to the directory page. A green flashbar displays at the top of your screen to indicate that you successfully began the launch.
To view directory administration EC2 instances
If you haven't launched any EC2 instances for a directory, a dash (-) displays under Directory administration EC2 instance.
Under Active Directory, choose Directories and select the directory you want to view.
Under Directory details, under Directory administration EC2 instance, choose one or all of your instances to view.
When you choose an instance, you're routed to the EC2 Connect to instance page to connect a remote desktop to your instance.