Amazon Managed Microsoft AD quotas - Amazon Directory Service
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Amazon Managed Microsoft AD quotas

The following are the default quotas for Amazon Managed Microsoft AD. Each quota is per Region unless otherwise noted.

Amazon Managed Microsoft AD quotas
Resource Default quota
Amazon Managed Microsoft AD directories 20
Manual snapshots * 5 per Amazon Managed Microsoft AD
Manual snapshots age ** 180 days
Maximum number of domain controllers per directory 20
Shared domains per Standard Microsoft AD *** 5
Shared domains per Enterprise Microsoft AD *** 125
Maximum number of registered certificate authority (CA) certificates per directory 5
Maximum number of total Amazon Regions in a single Amazon Managed Microsoft AD (Enterprise Edition) directory **** 5

* The manual snapshot quota cannot be changed.

** The maximum supported age of a manual snapshot is 180 days and cannot be changed. This is due to the Tombstone-Lifetime attribute of deleted objects which defines the useful shelf life of a system-state backup of Active Directory. It is not possible to restore from a snapshot older than 180 days. For more information, see Useful shelf life of a system-state backup of Active Directory on the Microsoft website.

*** The shared domain default quota refers to the number of accounts that an individual directory can be shared to.

**** This includes 1 primary Region and up to 4 additional Regions. For more information, see Primary vs additional Regions.


You cannot attach a public IP address to your Amazon elastic network interface (ENI).

For information regarding application design and load distribution, see Programming your applications.

For storage and object quotas, see the Comparison Table on the Amazon Directory Service Pricing page.