What gets created with your hybrid directory
When you create an Active Directory with Amazon Managed Microsoft AD (Hybrid Edition), Amazon Directory Service performs several tasks automatically on your behalf. This topic provides a comprehensive reference of every resource, account, organizational unit, delegated group, and group policy object that Amazon creates during directory provisioning.
The following resources are created automatically upon directory creation:
-
Elastic Network Interfaces (ENIs) for each domain controller
-
Active Directory domain controllers across two Availability Zones
-
Two Organizational Units (OUs) under the domain root
-
Amazon Delegated Groups for delegated permissions management
-
Group Policy Objects (GPOs) for domain security configuration
-
Default local accounts for Amazon management purposes
Elastic Network Interfaces and Domain Controllers
When provisioning a Hybrid directory, Amazon Directory Service automatically creates and associates an elastic network interface (ENI) with each of your domain controllers. These ENIs are essential for connectivity between your Amazon VPC and the Directory Service domain controllers.
Important
You should never delete these ENIs. You can identify all network interfaces
reserved for use with Directory Service by their description: "Amazon created network
interface for directory directory-id".
Domain Controller architecture
Amazon Directory Service provisions Active Directory within your VPC using two domain controllers by default, providing fault tolerance and high availability:
-
Domain controllers are deployed across two Availability Zones in a Region by default
-
Both domain controllers are connected to your Amazon VPC
-
Backups are automatically taken once per day
-
Amazon EBS volumes are encrypted to ensure data is secured at rest
-
Domain controllers that fail are automatically replaced in the same Availability Zone using the same IP address
-
Additional domain controllers can be provisioned for higher resiliency and performance after the directory is Active
DNS server configuration
The default DNS server of a Hybrid directory is the VPC DNS server at Classless Inter-Domain Routing (CIDR)+2. For more information, refer to the Amazon DNS server documentation in the Amazon VPC User Guide.
Note
Amazon does not allow the installation of monitoring agents on Amazon Managed Microsoft AD (Hybrid Edition) domain controllers.
Organizational Units (OUs)
Amazon Directory Service creates two Organizational Units (OUs) directly under your existing self-managed directory domain root. These OUs form the structural foundation for organizing directory objects, accounts, and delegated permissions within your Amazon Managed Microsoft AD (Hybrid Edition).
| OU Name | Description |
|---|---|
| Amazon Delegated Groups | Stores all of the groups that you can use to delegate Amazon-specific permissions to your users. |
| Amazon Reserved | Stores all Amazon management-specific accounts, including service-managed accounts used by Amazon services. |
Domain OU Structure Example
The following illustrates the default OU hierarchy for a domain named
corp.example.com (NetBIOS: Corp):
corp.example.com (domain root) Corp Amazon Delegated Groups Amazon Reserved
Amazon Delegated Groups
Amazon Directory Service creates a comprehensive set of security groups in the Amazon Delegated Groups OU. Each group is designed to delegate a specific set of Amazon and Active Directory permissions to your users, without requiring full domain administrator rights.
Note
You can add members to these Amazon Delegated Groups. Members of Amazon Delegated Administrators can manage all groups in the Amazon Delegated Groups OU.
| Group Name | Description |
|---|---|
| Amazon Delegated Account Operators | Members have limited account management capability such as password resets. |
| Amazon Delegated Active Directory Based Activation Administrators | Members can create Active Directory volume licensing activation objects, enabling enterprises to activate computers through a connection to their domain. |
| Amazon Delegated Add Workstations To Domain Users | Members can join 10 computers to a domain. |
| Amazon Delegated Administrators | Members can manage Amazon Managed Microsoft AD, have full control of all objects in your OU, and can manage groups in the Amazon Delegated Groups OU. |
| Amazon Delegated Allowed to Authenticate Objects | Members are provided the ability to authenticate to computer resources in the Amazon Reserved OU. Only needed for on-premises objects with Selective Authentication enabled Trusts. |
| Amazon Delegated Allowed to Authenticate to Domain Controllers | Members are provided the ability to authenticate to computer resources in the Domain Controllers OU. Only needed for on-premises objects with Selective Authentication enabled Trusts. |
| Amazon Delegated Deleted Object Lifetime Administrators | Members can modify the msDS-DeletedObjectLifetime object, which defines how long a deleted object will be available to recover from the AD Recycle Bin. |
| Amazon Delegated Distributed File System Administrators | Members can add and remove FRS, DFS-R, and DFS name spaces. |
| Amazon Delegated Domain Name System Administrators | Members can manage Active Directory integrated DNS. |
| Amazon Delegated Dynamic Host Configuration Protocol Administrators | Members can authorize Windows DHCP servers in the enterprise. |
| Amazon Delegated Enterprise Certificate Authority Administrators | Members can deploy and manage Microsoft Enterprise Certificate Authority infrastructure. |
| Amazon Delegated Fine Grained Password Policy Administrators | Members can modify precreated fine-grained password policies. |
| Amazon Delegated FSx Administrators | Members are provided the ability to manage Amazon FSx resources. |
| Amazon Delegated Group Policy Administrators | Members can perform group policy management tasks (create, edit, delete, link). |
| Amazon Delegated Kerberos Delegation Administrators | Members can enable delegation on computer and user account objects. |
| Amazon Delegated Managed Service Account Administrators | Members can create and delete Managed Service Accounts. |
| Amazon Delegated MS-NPRC Non-Compliant Devices | Members will be provided an exclusion from requiring secure channel communications with domain controllers. This group is for computer accounts. |
| Amazon Delegated Remote Access Service Administrators | Members can add and remove RAS servers from the RAS and IAS Servers group. |
| Amazon Delegated Replicate Directory Changes Administrators | Members can synchronize profile information in Active Directory with SharePoint Server. |
| Amazon Delegated Server Administrators | Members are included in the local administrators group on all domain-joined computers. |
| Amazon Delegated Sites and Services Administrators | Members can rename the Default-First-Site-Name object in Active Directory Sites and Services. |
| Amazon Delegated System Management Administrators | Members can create and manage objects in the System Management container. |
| Amazon Delegated Terminal Server Licensing Administrators | Members can add and remove Terminal Server License Servers from the Terminal Server License Servers group. |
| Amazon Delegated User Principal Name Suffix Administrators | Members can add and remove user principal name suffixes. |
Group Policy Objects (GPOs)
Amazon Directory Service creates and applies a set of Group Policy Objects (GPOs) to enforce security settings and administrative configurations across your Amazon Managed Microsoft AD (Hybrid Edition) domain controllers. These GPOs are pre-configured and maintained by Amazon.
Important
You do not have permissions to delete, modify, or unlink these GPOs. This is by design, as they are reserved for Amazon use. You may link them to OUs that you control if needed. To view the settings of each GPO, use the Group Policy Management Console (GPMC) from a domain-joined Windows instance.
| GPO Name | Applies to | Description |
|---|---|---|
| Amazon Reserved Policy:User | Amazon Reserved user accounts | Sets recommended security settings on all user accounts in the Amazon Reserved OU. |
| Amazon Hybrid Managed Active Directory Policy | All hybrid AD domain controllers | Sets recommended security settings on all domain controllers. |
| Amazon Managed AppLocker Policy | All hybrid AD domain controllers | Enforces code signing requirements for monitoring agents and other executables on Hybrid AD domain controllers. |
| TimePolicyNT5DS | All non-PDCe hybrid AD domain controllers | Sets all non-PDCe domain controllers time policy to use Windows Time (NT5DS). |
| TimePolicyPDC | The PDCe hybrid AD domain controller | Sets the PDCe domain controller's time policy to use Network Time Protocol (NTP). |
Fine-Grained Password Policy
A Fine-Grained Password Policy is applied to enforce password requirements for accounts in the Amazon Reserved OU.
Default local accounts
Amazon Directory Service creates several default accounts in your Amazon Managed Microsoft AD (Hybrid Edition) during provisioning. These accounts serve different operational roles and are managed in distinct ways.
Admin account
The Admin account is the directory administrator account created when the hybrid directory is first provisioned. This account is used by Amazon Directory Service to manage your hybrid AD domain controllers.
-
Username: Random
-
Location: Amazon Reserved OU
-
Purpose: Manage your Active Directory in the Amazon Web Services Cloud
-
Access: This account is only accessible by Amazon Directory Service and cannot be used by end-users
AWS_11111111111 (Service-Managed Accounts)
Any account name beginning with AWS_ followed by an underscore and
located in the Amazon Reserved OU is a service-managed account. These accounts are
used by Amazon services to interact with the Active Directory.
-
Account format:
AWS_followed by an account identifier (e.g.,AWS_11111111111) -
Location: Amazon Reserved OU
-
Created when: Amazon Directory Service Data is enabled, or when a new Amazon application is authorized on Active Directory
-
Access: These accounts are only accessible by Amazon services and cannot be used by end-users
krbtgt account
The krbtgt account plays a critical role in the Kerberos authentication infrastructure of your Amazon Managed Microsoft AD (Hybrid Edition). This special account is used for Kerberos ticket-granting ticket (TGT) encryption and is integral to the security of all Kerberos-based authentication within the domain.
Group Managed Service Accounts (gMSA)
Amazon Directory Service creates a Group Managed Service Account (gMSA) in the Amazon Reserved OU to support internal service authentication.
Hybrid Administration Groups
Amazon Directory Service creates a set of security groups in the Amazon Reserved OU. Each group is designed to perform administrative tasks for your hybrid directory domain controllers.
| Group Name | Description |
|---|---|
| Amazon Administrators | Members have full control of all sub-objects in the customer OU and group management rights in Amazon Delegated Groups OU. |
| Amazon Service Administrators | Hybrid directory specific complete unrestricted access to the computer/domain including the Amazon Reserved OU. |
| Amazon Object Management Service Accounts | Highly privileged group for managing Amazon hybrid directory full control over users and groups in customer OU. |
| Amazon Private CA Connector for AD Delegated Group | Used by Amazon Private CA Connector for AD READ access to customer OU, READ/WRITE for CA objects. |
| Amazon Application and Service Delegated Group | Used for Amazon Application/Service delegation manages SPNs on computer objects and creates GPOs. |