Preparation

Preparation

  1. 1 VPC
  2. 2 Private Subnets
  3. 2 Public Subnets
  4. AWS Directory Service: Deploy an AWS Managed Directory Service
  5. NAT Gateway
  6. Internet Gateway
  7. 1 EC2 - Bastion host
    • Public Subnet
    • Assigned Public IP: Enabled
    • IAM Role: Attached
    • Domain: Joined Domain
    • Modify hosts file and Computer name: recommended to do but not required
    • Modify IP: YES
  8. 1 EC2 - AD Manager
    • Private Subnet
    • Assigned Public IP: Disabled
    • IAM Role: Attached
    • Domain: Joined Domain
    • Modify hosts file and Computer name: recommended to do but not required
    • Modify IP: YES

Refer to the architect diagram bellow to double check your preparation for the lab

Amazon Workspace


Quick deployment with AWS CloudFormation

If you do not want to create every resource above manually, use the CloudFormation template below. The template provisions the entire Preparation section so that you can jump straight to 3.1 - Prepare To Deploy Amazon WorkSpaces.

Download the template: workshop-prerequisites.yaml

Parameters to fill in

ParameterDescription
AvailabilityZone1 / AvailabilityZone22 different AZs, must be AZs that support Amazon WorkSpaces (for example us-east-1a and us-east-1c)
AllowedRdpCidrYour own public IP in CIDR form ending with /32. Get your IP at checkip.amazonaws.com
KeyNameKey pair used to decrypt the Administrator password for the first RDP session
DirectoryAdminPasswordPassword for the domain Admin account, must satisfy complexity rules
DirectoryName / DirectoryShortNameDomain name, defaults to corp.example.com / CORP
BastionInstanceTypeInstance type for the Bastion host, defaults to t3.medium
AdManagerInstanceTypeInstance type for the AD-Manager, defaults to t3.large

Amazon WorkSpaces is not available in every AZ of a Region. If you pick an unsupported AZ, the directory registration step in section 3.1 will fail. You should create the stack in the us-east-1, us-west-2 or ap-southeast-1 Region.

For AllowedRdpCidr, open checkip.amazonaws.com to get your real public IP and append /32. Do not paste example IPs such as 203.0.113.x — that range belongs to RFC 5737, it is reserved for documentation only and belongs to nobody, so the Security Group will block everything and you will not be able to RDP into the Bastion host. Your ISP public IP can also change, so if RDP suddenly stops working, check your current IP and update the inbound rule.

Deploy from the AWS Management Console

  1. Sign in to the AWS Management Console and select the Region you want to work in

  2. Search for and open CloudFormation => Create stack => With new resources (standard)

  3. Choose Upload a template file => select the workshop-prerequisites.yaml file you just downloaded => Next Amazon Workspace

  4. Enter a Stack name, for example workspaces-workshop, then fill in the parameters from the table above => Next Amazon Workspace Amazon Workspace

  5. On the Configure stack options page, select I acknowledge that AWS CloudFormation might create IAM resources => Next
    Amazon Workspace

  6. On the Review page choose Submit Amazon Workspace

After the stack completes

AWS Managed Microsoft AD needs about 20 - 25 minutes to initialize, so the total stack creation time is usually around 25 - 30 minutes. When the stack reaches CREATE_COMPLETE, open the Outputs tab to collect the information needed for section 3:

OutputUsed for
DirectoryIdThe directory to register with Amazon WorkSpaces in step 3.1
WorkSpacesSubnetIdsThe 2 Private Subnets to select when registering the directory
BastionPublicIpRDP into the bastion, sign in as CORP\Admin
AdManagerPrivateIpFrom the bastion, RDP here to use Active Directory Users and Computers
DirectoryDnsAddressesThe 2 DNS IPs of the Domain Controllers