AWS- Type of Directory Services Offered

Directory Service optionDescriptionBest for..
AWS Cloud DirectoryCloud-native directory to share and control access to hierarchical data between applicationsCloud applications that need hierarchical data with complex relationships
Amazon CognitoSign-up and sign-in functionality that scales to millions of users and federated to public social media servicesDevelo consumer apps or SaaS
AWS Directory Service for Microsoft Active DirectoryAWS-managed full Microsoft AD (Standard or enterprise) running on Windows server 2012 R2Enterprises that want hosted Microsoft AD or you need LDAP for Linux apps
AD connectorAllows on-premises users to log into AWS services with their existing AD credentials. Also allows EC2 instances to join AD domainSingle Sign-on for on-prem employees and for adding EC2 instances to the domain
Simple ADLow Scale, low cost AD implementation based on SambaSimple user directory, or you need LDAP compatibility

AD Connector vs Simple AD

AD connectorSimple AD
Must have existing ADStandalone AD based on Samba AD
Existing AD users can access AWS resources using IAM rolesSupports user account groups, group policies, Domains
Supports MFA with existing RADIUS based infraKerbros based SSO
No MFA support
No trust relationship

Leave a comment