A financial services company is migrating its Microsoft SQL Server databases and SharePoint servers to AWS. The company maintains an on-premises Microsoft Active Directory domain containing all employee user accounts. The company deploys AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) in a new AWS VPC. The solutions architect must configure a solution that allows employees to access the AWS-hosted SharePoint servers using their existing on-premises credentials.
Which combination of actions should the solutions architect take to meet these requirements? (Select two.)
- Establish network connectivity between the VPC and the on-premises network, and configure conditional DNS forwarders on both the on-premises DNS servers and the AWS Managed Microsoft AD domain controllers.Cevap
- Configure a forest trust relationship between the on-premises Active Directory domain and the AWS Managed Microsoft AD domain.Cevap
- CCreate individual IAM users in the AWS account for each on-premises employee to enable console and API access.
- DUse the AWS account root user credentials to manage the Active Directory domain controllers and delegate access rights.
- EStore the on-premises Active Directory domain administrator credentials as a plaintext parameter in Systems Manager Parameter Store to automate trust verification.
Cevap
Establishing network connectivity and DNS forwarders between the networks, and configuring a forest trust relationship between the on-premises Active Directory domain and the AWS Managed Microsoft AD domain.
To integrate an on-premises Active Directory with AWS Managed Microsoft AD using a forest trust, you must first establish network connectivity (via Site-to-Site VPN or AWS Direct Connect) and configure conditional DNS forwarders on both sides so that the domains can resolve each other. After these prerequisites are satisfied, configuring a forest trust allows authentication requests to be securely routed from AWS Managed Microsoft AD to the on-premises domain controllers, enabling on-premises users to access the AWS-hosted resources with their current credentials.
Adım Adım Çözüm
Anahtar Kavram
Establishing a hybrid identity model using AWS Managed Microsoft AD forest trust relationships.
Tahmini Süre:2m 0s