Creating an Amazon Managed Microsoft AD group
Use the following procedure to create an Amazon Managed Microsoft AD group with Amazon Directory Service Data in the Amazon Web Services Management Console, Amazon CLI, or Amazon Tools for PowerShell.
Before you begin, complete the following:
-
Enable user and group management for Directory Service Data. You can only enable this feature from the Primary Amazon Web Services Region for your directory. For more information, see Primary vs additional Regions.
-
You'll need the necessary IAM permissions to use Amazon Directory Service Data. To get started, you can use the Amazon managed policy: AWSDirectoryServiceDataFullAccess or Amazon managed policy: AWSDirectoryServiceDataReadOnlyAccess. For more information, see Amazon Directory Service API permissions: Actions, resources, and conditions reference and Security best practices in IAM.