Soru

Zorluk: OrtaIdentity Federation and Directory Services

A financial services company is migrating its Microsoft SQL Server databases and SharePoint servers to AWS. The company maintains an on-premises Microsoft Active Directory domain containing all employee user accounts. The company deploys AWS Directory Service for Microsoft Active Directory (AWS Managed Microsoft AD) in a new AWS VPC. The solutions architect must configure a solution that allows employees to access the AWS-hosted SharePoint servers using their existing on-premises credentials.

Which combination of actions should the solutions architect take to meet these requirements? (Select two.)

  1. Establish network connectivity between the VPC and the on-premises network, and configure conditional DNS forwarders on both the on-premises DNS servers and the AWS Managed Microsoft AD domain controllers.Cevap
  2. Configure a forest trust relationship between the on-premises Active Directory domain and the AWS Managed Microsoft AD domain.Cevap
  3. C
    Create individual IAM users in the AWS account for each on-premises employee to enable console and API access.
  4. D
    Use the AWS account root user credentials to manage the Active Directory domain controllers and delegate access rights.
  5. E
    Store the on-premises Active Directory domain administrator credentials as a plaintext parameter in Systems Manager Parameter Store to automate trust verification.

Cevap

Establishing network connectivity and DNS forwarders between the networks, and configuring a forest trust relationship between the on-premises Active Directory domain and the AWS Managed Microsoft AD domain.
To integrate an on-premises Active Directory with AWS Managed Microsoft AD using a forest trust, you must first establish network connectivity (via Site-to-Site VPN or AWS Direct Connect) and configure conditional DNS forwarders on both sides so that the domains can resolve each other. After these prerequisites are satisfied, configuring a forest trust allows authentication requests to be securely routed from AWS Managed Microsoft AD to the on-premises domain controllers, enabling on-premises users to access the AWS-hosted resources with their current credentials.

Adım Adım Çözüm

1
Configure network routing and DNS resolution.
Domain controllers in both the on-premises network and the AWS VPC can communicate over the network and resolve each other's fully qualified domain names.
A trust relationship requires DNS resolution of the partner domain name and active network pathways (such as VPN or Direct Connect) to route LDAP traffic.
2
Establish the forest trust relationship.
A secure trust relationship is configured on both sides to allow users in the on-premises domain to authenticate to services joined to the AWS Managed Microsoft AD domain.
This trust enables AWS Managed Microsoft AD to delegate user authentication back to the on-premises Active Directory without needing to replicate passwords.

Anahtar Kavram

Establishing a hybrid identity model using AWS Managed Microsoft AD forest trust relationships.
Tahmini Süre:2m 0s
Bu soruyu puanla