Tutorial: Sharing your Amazon Managed Microsoft AD directory for seamless EC2 domain-join - Amazon Directory Service
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Tutorial: Sharing your Amazon Managed Microsoft AD directory for seamless EC2 domain-join

This tutorial shows you how to share your Amazon Managed Microsoft AD directory (the directory owner account) with another Amazon Web Services account (the directory consumer account). Once the networking prerequisites have been completed, you will share a directory between two Amazon Web Services accounts. Then you'll learn how to seamlessly join an EC2 instance to a domain in the directory consumer account.

We recommend that you first review directory sharing key concepts and use case content before you start work on this tutorial. For more information, see Key directory sharing concepts.

The process for sharing your directory differs depending on whether you share the directory with another Amazon Web Services account in the same Amazon organization or with an account that is outside of the Amazon organization. For more information about how sharing works, see Sharing methods.

This workflow has four basic steps.

Steps to share Amazon Managed Microsoft AD: Set up your networking environment, share your directory, accept shared directory invite, and test seamlessly join an Amazon EC2 instance for Windows Server to a domain.
Step 1: Set up your networking environment

In the directory owner account, you set up all of the networking prerequisites necessary for the directory sharing process.

Step 2: Share your directory

While signed in with directory owner administrator credentials, you open the Amazon Directory Service console and start the share directory workflow, which sends an invitation to the directory consumer account.

Step 3: Accept shared directory invite - Optional

While signed in with directory consumer administrator credentials, you open the Amazon Directory Service console and accept the directory sharing invite.

Step 4: Test seamlessly joining an EC2 instance for Windows Server to a domain

Finally, as the directory consumer administrator, you attempt to join an EC2 instance to your domain and verify that it works.

Additional resources