AWS Directory Service for Microsoft Active Directory, also known as AWS Managed Microsoft AD, enables your directory-aware workloads and AWS resources to use managed Active Directory in AWS. It provides a fully managed, highly available Microsoft Active Directory in the AWS Cloud, with features including trust relationships, domain controllers, LDAPS, and multi-account directory sharing.
Tags: Active Directory, Authentication, AWS, Directory Services, Identity Management
Created: 2026-03-16 | Modified: 2026-04-19
- AWS Directory Service API - Provides programmatic access to create and manage directories, trusts, snapshots, and domain controllers for Microsoft Active Directory in the AWS Cloud.
| Feature |
Description |
| Managed Microsoft AD |
Fully managed AWS Managed Microsoft Active Directory with automatic patching and monitoring |
| Simple AD |
Standalone managed directory powered by Samba 4 for basic AD functionality |
| AD Connector |
Proxy service for connecting AWS applications to existing on-premises AD |
| Trust Relationships |
One-way and two-way trust relationships between AWS and on-premises directories |
| Multi-Region Replication |
Replicate your AWS Managed Microsoft AD across multiple AWS Regions |
| Directory Sharing |
Share a single directory across multiple AWS accounts and VPCs |
| Use Case |
Description |
| Hybrid Identity |
Extend on-premises Active Directory into AWS for unified identity management |
| Workload Authentication |
Enable Windows and Linux workloads to join and authenticate against managed AD |
| AWS Application Integration |
Use managed AD for AWS WorkSpaces, RDS, and other AD-aware services |
| LDAPS Encryption |
Secure LDAP communications with certificates for compliance requirements |
| Disaster Recovery |
Use directory snapshots for point-in-time recovery of directory data |
| Integration |
Description |
| Amazon WorkSpaces |
Join WorkSpaces desktops to managed AD for enterprise desktop management |
| Amazon RDS |
Enable Windows Authentication for SQL Server RDS instances via managed AD |
| AWS IAM Identity Center |
Use managed AD as identity source for centralized access management |
| AWS CloudTrail |
Audit all Directory Service API calls for compliance and security monitoring |
| Amazon SNS |
Receive directory event notifications via SNS topic subscriptions |
| Name |
Description |
File |
| Amazon Directory Service API |
Shared Naftiko capability definition for Directory Service API operations |
directory-service-api.yaml |
| Workflow |
Description |
Tools |
Personas |
File |
| Active Directory Management |
End-to-end Active Directory lifecycle management using Amazon Directory Service |
14 |
Identity Engineer, Cloud Architect |
active-directory-management.yaml |