SlideShare a Scribd company logo
AMAZON WORKSPACES
OVERVIEW
By John Louis Garcia
Senior AWS Architect
04/14/2020
Introduction
Amazon Workspaces is
a manage secured
Desktop as a Service
(DaaS) desktop
solution.
Getting Started
1. You must have an AWS account to create or administer a WorkSpace. Users do not need an AWS account
to connect to and use their WorkSpaces.
2. When you launch a WorkSpace, you must select a WorkSpace bundle. For more information, see Amazon
WorkSpaces Bundles.
3. When you launch a WorkSpace, you must specify profile information for the user, including a user name
and email address. Users complete their profiles by specifying a password. Information about
WorkSpaces and users is stored in a directory.
4. Amazon WorkSpaces is not available in every Region. Verify the supported Regions and select a Region
for your WorkSpaces. For more information about the supported Regions, see Amazon WorkSpaces
Pricing by AWS Region.
Options
1. Quick Setup
• For an individual / small group of cloud-based users.
2. Advanced Setup
• For advanced setup that includes on-premise connectivity, Microsoft AD with Amazon VPC
Requirements
A. Virtual Private Cloud
(VPC)
You’ll need a minimum of two subnets for a
WorkSpaces deployment because each AWS
Directory Service construct requires two subnets in
a Multi-AZ deployment.
Requirements
B. Directory Service
AD Connector — Use your existing on-premises Microsoft Active Directory. Users can
sign into their WorkSpaces using their on-premises credentials and access on-premises
resources from their WorkSpaces.
Microsoft AD — Create a Microsoft Active Directory hosted on AWS.
Simple AD — Create a directory that is compatible with Microsoft Active Directory,
powered by Samba 4, and hosted on AWS.
Cross trust — Create a trust relationship between your Microsoft AD directory and your
on-premises domain.
Amazon Cognito User Pools — With user pools, you can add user registration and sign-
in features to your apps. Users can sign in with an email address, phone number, or
username rather than use an external identity provider like Facebook or Google. You can
also create custom registration fields and store that metadata in your user directory. You
can verify email addresses and phone numbers, recover passwords, and enable multi-
factor authentication (MFA) with just a few lines of code.
Requirements
C. Workspaces Client
Android Client Application, iPad Client Application, Linux Client, Application, macOS
Client Application, PCoIP Zero Client, Web Access, Windows Client Application
Supported Regions
AWS Service Americas Europe/Middle East/Africa Asia Pacific
Amazon Workspaces Northern Virginia,
Oregon,
Montreal,
São Paulo,
AWS GovCloud (US-West)
Ireland, Frankfurt, London Singapore, Tokyo, Sydney,
Seoul, Ningxia*
Amazon Workspace
Application Manager
(WAM)
Northern Virginia,
Oregon,
Ireland Singapore, Sydney
Amazon Workdocs Northern Virginia,
Oregon,
Ireland Singapore, Tokyo, Sydney
https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/
Workspaces Diagram
Workspaces Diagram 2
USERS
AMAZON
WORKSPACES
CORPORATE
DATA CENTER
AWS CLOUD
* SERVERS
* APPLICATIONS
* DATABASES
Bundles and Images
A WorkSpace bundle is a combination of an operating system, and storage, compute, and
software resources. When you launch a WorkSpace, you select the bundle that meets your
needs. The default bundles available for WorkSpaces are called public bundles. For more
information about the various public bundles available for Amazon WorkSpaces, see Amazon
WorkSpaces Bundles.
If you've launched a Windows or Amazon Linux WorkSpace and have customized it, you can
create a custom image from that WorkSpace.
A custom image contains only the OS, software, and settings for the WorkSpace. A custom
bundle is a combination of both that custom image and the hardware from which a
WorkSpace can be launched.
Amazon WorkSpaces offers Amazon Linux WorkSpaces built on Amazon Linux 2 LTS, or
Windows 10 desktop experiences. The Windows 10 desktop experiences is powered by
Windows Server 2016. If your organization is eligible to bring their own Windows Desktop
licenses, you can run the Windows 10 Enterprise operating system on your Amazon
WorkSpaces.
Bundles and Images
Workspaces Application Manager (WAM)
Amazon WorkSpaces Application Manager
(Amazon WAM) offers a fast, flexible, and
secure way for you to deploy and manage
applications for Amazon WorkSpaces. Amazon
WAM accelerates software deployment,
upgrades, patching, and retirement by
packaging Microsoft Windows desktop
applications into virtualized application
containers. These applications run on the end-
user’s Amazon WorkSpaces instance as though
they are natively installed.
Amazon Workdocs
Amazon WorkDocs is a fully managed, secure content
creation, storage, and collaboration service. With
Amazon WorkDocs, you can easily create, edit, and
share content, and because it’s stored centrally on
AWS, access it from anywhere on any device. Amazon
WorkDocs makes it easy to collaborate with others,
and lets you easily share content, provide rich
feedback, and collaboratively edit documents. You can
use Amazon WorkDocs to retire legacy file share
infrastructure by moving file shares to the cloud.
Amazon WorkDocs lets you integrate with your
existing systems and offers a rich API so that you can
develop your own content-rich applications. Amazon
WorkDocs is built on AWS, where your content is
secured on the world's largest cloud infrastructure.
Launching a workspace
1. Workspace Administrator will launch the workspace. Administrator will select the directory, create the
user and add it to directory. Select the bundle and configure the workspace. Choose the running mode
(always on / autostop). Select encryption.
2. User will receive a verification email that will require the user to click on a provided URL. The email
will contain a registration code.
3. User will require a change of password.
4. User will use the registration when logging in from the workspace client.
5. User will need to download from https://clients.amazonworkspaces.com/ and install the workspace
client.
Workspace Limits
By default, a single AWS account can have a maximum of 5 WorkSpaces per region.
The following information must be included in the "Use case description" if the limit increase request is for more
than 200 WorkSpaces or more than 20 Graphics/GraphicsPro WorkSpaces:
Is this request for Coronavirus Disease 2019 (COVID-19) DR/BR planning purposes, or for a planned
rollout/scale up?
What percentage of your overall user base does this request cover?
What percentage of your users do you expect to use WorkSpaces if you have alternative method to have users
connect to your network such as VPN?
What percentage of your WorkSpaces will be using Always On running mode?
What percentage of your WorkSpaces will be using AutoStop running mode?
What bundle type(s) are you planning to use (Value, Standard, Performance, Power, PowerPro, Graphics,
GraphicsPro)?
If more than one type, please add approximate percentage for each.
What is the target date/date range to ramp up to these WorkSpaces?
Will you deploy them in batches or on demand if user requests?
Do you plan on using BYOL (dedicated hardware) WorkSpaces?
Workspaces Diagram 3
DEMO
Tips
1. The following ports needs to be allowed in your firewall.
• Web Browser (HTTPS 443)
• Application Client (TCP and UDP 4175)
2. A minimum of 1 Mbps per simultaneous user watching a 480p video window.
3. When designing a VPC, always think about the future scenarios. Design a network that has enough IP Ranges
for your requirements for you cannot rebuild this later.
4. When choosing a Directory Service, always think about the future scenarios. If you are resolving your DNS
from an Active Directory trust, don’t use Simple AD.
5. If you need to check which Region has the best latency from your location, go to
https://clients.amazonworkspaces.com/Health.html.
6. When you use the Workspace Application Manager (WAM) and you can’t see the shortcut icon from your
workspace desktop, reboot your workspace. If not open command prompt and do the following.
c:
cd C:Program FilesAmazon
WorkSpacesApplicationManager.exe
7. If you can’t see any applications in your WAM Application Client, go to APPS then choose DISCOVER.
8. Always be mindful on the supported regions.
Tips
9. Each WorkSpace is assigned to a single user and cannot be shared by multiple users.
10. By default, web access (browser) is disabled. To enable, go to directories, click on the dropdown and select
update details. Click on the Access Control Option and select “web access” on the list.
11. Workspace can also include Microsoft Office 2010, 2013, 2016. It comes with an additional cost.
12. You can build your own applications on WAM.
13. You can create group policies on your Microsoft Active Directory.
14. If you want to build your own catalog (apps) and use them in WAM, you will need to build WAM Servers
(WAM Player and WAM Studio). These servers doesn’t need to be hosted inside your workspace VPC. You can
deploy this to any VPC as long as it has an internet connection.
15. You can reset your user password by going to the aws directory services. Select your directory and click
reset user password.
16. You can also connect to the workspace via RDP as long the security groups allows it and the workspace has
access to the internet. Once connected, you will also need to authenticate to login.
17. You can restrict access only for trusted devices. You will need to create the certificates, deploy the client
cert to your trusted device and configure your setting from the AWS dashboard (Directories then Access
Control Options). https://docs.aws.amazon.com/workspaces/latest/adminguide/trusted-devices.html
Links
Amazon Workspaces Documentation
https://docs.aws.amazon.com/workspaces/index.html
User Guide
https://docs.aws.amazon.com/workspaces/latest/userguide/workspaces-ug.pdf
Best Practices
https://d1.awsstatic.com/whitepapers/workspaces/Best_Practices_for_Deploying_Ama
zon_WorkSpaces.pdf
Multi Factor Authentication
https://docs.aws.amazon.com/workspaces/latest/adminguide/update-directory-
details.html#connect-mfa
FAQ
https://aws.amazon.com/workspaces/faqs/

More Related Content

What's hot

How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003
How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003
How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003LiquidHub
 
HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris...
 HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris... HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris...
HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris...
Amazon Web Services
 
Windows azure camp
Windows azure campWindows azure camp
Windows azure camp
Abhishek Sur
 
Webinar: Efficient Disaster Recover with Cloud Computing
Webinar: Efficient Disaster Recover with Cloud ComputingWebinar: Efficient Disaster Recover with Cloud Computing
Webinar: Efficient Disaster Recover with Cloud Computing
Edureka!
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
Khushboo Wadhwani
 
Open Mic IBM connections and IBM Verse on premise integration
Open Mic IBM connections and IBM Verse on premise integrationOpen Mic IBM connections and IBM Verse on premise integration
Open Mic IBM connections and IBM Verse on premise integration
jayeshpar2006
 
Deploying MediaWiki On IBM DB2 in the Cloud
Deploying MediaWiki On IBM DB2 in the CloudDeploying MediaWiki On IBM DB2 in the Cloud
Deploying MediaWiki On IBM DB2 in the CloudLeons Petražickis
 
Developer ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrial
Developer ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrialDeveloper ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrial
Developer ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrialNitu Parimi
 
Working with azure database services platform
Working with azure database services platformWorking with azure database services platform
Working with azure database services platform
ssuser79fc19
 
Wordcamp Thessaloniki 2011 Wordpress and Microsoft Web Platform
Wordcamp Thessaloniki 2011 Wordpress and Microsoft Web PlatformWordcamp Thessaloniki 2011 Wordpress and Microsoft Web Platform
Wordcamp Thessaloniki 2011 Wordpress and Microsoft Web PlatformGeorge Kanellopoulos
 
Wordcamp Thessaloniki 2011 The Nextweb
Wordcamp Thessaloniki 2011 The NextwebWordcamp Thessaloniki 2011 The Nextweb
Wordcamp Thessaloniki 2011 The NextwebGeorge Kanellopoulos
 
Get your site microsoft edge ready
Get your site microsoft edge readyGet your site microsoft edge ready
Get your site microsoft edge ready
Mostafa
 
Web server hardware and software
Web server hardware and softwareWeb server hardware and software
Web server hardware and softwareVikram g b
 
The Hybrid Windows Azure Application
The Hybrid Windows Azure ApplicationThe Hybrid Windows Azure Application
The Hybrid Windows Azure Application
Michael Collier
 
Connect2016 - 1172 Shipping domino
Connect2016 - 1172 Shipping dominoConnect2016 - 1172 Shipping domino
Connect2016 - 1172 Shipping domino
Matteo Bisi
 

What's hot (18)

How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003
How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003
How To Configure Email Enabled Lists In Moss2007 Rtm Using Exchange 2003
 
HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris...
 HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris... HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris...
HK-AWS Hands-on Lab-Series-2019-for-Enterprise:-Data-Protection-in-Enterpris...
 
Windows azure camp
Windows azure campWindows azure camp
Windows azure camp
 
Data load utility
Data load utilityData load utility
Data load utility
 
Webinar: Efficient Disaster Recover with Cloud Computing
Webinar: Efficient Disaster Recover with Cloud ComputingWebinar: Efficient Disaster Recover with Cloud Computing
Webinar: Efficient Disaster Recover with Cloud Computing
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
 
Open Mic IBM connections and IBM Verse on premise integration
Open Mic IBM connections and IBM Verse on premise integrationOpen Mic IBM connections and IBM Verse on premise integration
Open Mic IBM connections and IBM Verse on premise integration
 
Deploying MediaWiki On IBM DB2 in the Cloud
Deploying MediaWiki On IBM DB2 in the CloudDeploying MediaWiki On IBM DB2 in the Cloud
Deploying MediaWiki On IBM DB2 in the Cloud
 
Infra Project report2
Infra Project report2Infra Project report2
Infra Project report2
 
Developer ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrial
Developer ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrialDeveloper ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrial
Developer ExperienceAWS_Oracle_Azure_Heroku_DigitaOceanCloudFreeTrial
 
Working with azure database services platform
Working with azure database services platformWorking with azure database services platform
Working with azure database services platform
 
Wordcamp Thessaloniki 2011 Wordpress and Microsoft Web Platform
Wordcamp Thessaloniki 2011 Wordpress and Microsoft Web PlatformWordcamp Thessaloniki 2011 Wordpress and Microsoft Web Platform
Wordcamp Thessaloniki 2011 Wordpress and Microsoft Web Platform
 
Word camp microsoft web platform
Word camp microsoft web platformWord camp microsoft web platform
Word camp microsoft web platform
 
Wordcamp Thessaloniki 2011 The Nextweb
Wordcamp Thessaloniki 2011 The NextwebWordcamp Thessaloniki 2011 The Nextweb
Wordcamp Thessaloniki 2011 The Nextweb
 
Get your site microsoft edge ready
Get your site microsoft edge readyGet your site microsoft edge ready
Get your site microsoft edge ready
 
Web server hardware and software
Web server hardware and softwareWeb server hardware and software
Web server hardware and software
 
The Hybrid Windows Azure Application
The Hybrid Windows Azure ApplicationThe Hybrid Windows Azure Application
The Hybrid Windows Azure Application
 
Connect2016 - 1172 Shipping domino
Connect2016 - 1172 Shipping dominoConnect2016 - 1172 Shipping domino
Connect2016 - 1172 Shipping domino
 

Similar to AWS Workspaces Overview v2

Masterclass - Amazon WorkSpaces
Masterclass - Amazon WorkSpacesMasterclass - Amazon WorkSpaces
Masterclass - Amazon WorkSpaces
Amazon Web Services
 
Moving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpacesMoving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpaces
Amazon Web Services
 
Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...
Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...
Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...
Amazon Web Services
 
A Step By Step Guide To Put DB2 On Amazon Cloud
A Step By Step Guide To Put DB2 On Amazon CloudA Step By Step Guide To Put DB2 On Amazon Cloud
A Step By Step Guide To Put DB2 On Amazon CloudDeepak Rao
 
McrUmbMeetup 22 May 14: Umbraco and Amazon
McrUmbMeetup 22 May 14: Umbraco and AmazonMcrUmbMeetup 22 May 14: Umbraco and Amazon
McrUmbMeetup 22 May 14: Umbraco and Amazon
Dan Lister
 
SoftNAS Cloud NAS Architecture on AWS whitepaper
SoftNAS Cloud NAS Architecture on AWS whitepaperSoftNAS Cloud NAS Architecture on AWS whitepaper
SoftNAS Cloud NAS Architecture on AWS whitepaper
MH Riad
 
SoftNAS Architecture on AWS
SoftNAS Architecture on AWSSoftNAS Architecture on AWS
SoftNAS Architecture on AWS
Buurst
 
Amazon Workspaces Master Class
Amazon Workspaces Master ClassAmazon Workspaces Master Class
Amazon Workspaces Master Class
Richard Harvey
 
Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...
Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...
Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...
AWS Germany
 
Aws big picture_overview
Aws big picture_overviewAws big picture_overview
Aws big picture_overview
Ajay Bidari
 
Amazon WorkSpaces for Education
Amazon WorkSpaces for EducationAmazon WorkSpaces for Education
Amazon WorkSpaces for Education
Amazon Web Services
 
Getting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocs
Getting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocsGetting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocs
Getting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocs
Amazon Web Services
 
Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...
Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...
Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...
Amazon Web Services
 
Amazon WorkSpaces: Advanced Topics and Application Delivery
Amazon WorkSpaces: Advanced Topics and Application DeliveryAmazon WorkSpaces: Advanced Topics and Application Delivery
Amazon WorkSpaces: Advanced Topics and Application Delivery
Amazon Web Services
 
Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...
Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...
Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...
Amazon Web Services
 
Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011
Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011
Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011
SugarCRM
 
Cloud Computing Amazon
Cloud Computing AmazonCloud Computing Amazon
Cloud Computing Amazon
OpenSource Technologies Pvt. Ltd.
 
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdfDumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
Dumps Cafe
 
Amazon WorkSpaces - Fully Managed Desktops in the Cloud
Amazon WorkSpaces - Fully Managed Desktops in the CloudAmazon WorkSpaces - Fully Managed Desktops in the Cloud
Amazon WorkSpaces - Fully Managed Desktops in the Cloud
Amazon Web Services
 
Single Sign-On for APEX applications based on Kerberos (Important: latest ver...
Single Sign-On for APEX applications based on Kerberos (Important: latest ver...Single Sign-On for APEX applications based on Kerberos (Important: latest ver...
Single Sign-On for APEX applications based on Kerberos (Important: latest ver...
Niels de Bruijn
 

Similar to AWS Workspaces Overview v2 (20)

Masterclass - Amazon WorkSpaces
Masterclass - Amazon WorkSpacesMasterclass - Amazon WorkSpaces
Masterclass - Amazon WorkSpaces
 
Moving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpacesMoving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpaces
 
Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...
Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...
Automating Amazon WorkSpaces Desktop and AppStream 2.0 Application Provisioni...
 
A Step By Step Guide To Put DB2 On Amazon Cloud
A Step By Step Guide To Put DB2 On Amazon CloudA Step By Step Guide To Put DB2 On Amazon Cloud
A Step By Step Guide To Put DB2 On Amazon Cloud
 
McrUmbMeetup 22 May 14: Umbraco and Amazon
McrUmbMeetup 22 May 14: Umbraco and AmazonMcrUmbMeetup 22 May 14: Umbraco and Amazon
McrUmbMeetup 22 May 14: Umbraco and Amazon
 
SoftNAS Cloud NAS Architecture on AWS whitepaper
SoftNAS Cloud NAS Architecture on AWS whitepaperSoftNAS Cloud NAS Architecture on AWS whitepaper
SoftNAS Cloud NAS Architecture on AWS whitepaper
 
SoftNAS Architecture on AWS
SoftNAS Architecture on AWSSoftNAS Architecture on AWS
SoftNAS Architecture on AWS
 
Amazon Workspaces Master Class
Amazon Workspaces Master ClassAmazon Workspaces Master Class
Amazon Workspaces Master Class
 
Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...
Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...
Vom Server bis zum Workspace: Windows Anwendungen auf AWS - AWS Cloud Web Day...
 
Aws big picture_overview
Aws big picture_overviewAws big picture_overview
Aws big picture_overview
 
Amazon WorkSpaces for Education
Amazon WorkSpaces for EducationAmazon WorkSpaces for Education
Amazon WorkSpaces for Education
 
Getting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocs
Getting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocsGetting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocs
Getting Started with AWS Enterprise Applications: WorkSpaces, WorkMail, WorkDocs
 
Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...
Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...
Amazon WorkSpaces and Amazon WorkSpaces Application Manager: Delivering Cloud...
 
Amazon WorkSpaces: Advanced Topics and Application Delivery
Amazon WorkSpaces: Advanced Topics and Application DeliveryAmazon WorkSpaces: Advanced Topics and Application Delivery
Amazon WorkSpaces: Advanced Topics and Application Delivery
 
Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...
Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...
Well-architected Amazon WorkSpaces: Enterprise deployment at scale - SVC304 -...
 
Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011
Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011
Sweet! Running SugarCRM on the Amazon Cloud | SugarCon 2011
 
Cloud Computing Amazon
Cloud Computing AmazonCloud Computing Amazon
Cloud Computing Amazon
 
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdfDumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
 
Amazon WorkSpaces - Fully Managed Desktops in the Cloud
Amazon WorkSpaces - Fully Managed Desktops in the CloudAmazon WorkSpaces - Fully Managed Desktops in the Cloud
Amazon WorkSpaces - Fully Managed Desktops in the Cloud
 
Single Sign-On for APEX applications based on Kerberos (Important: latest ver...
Single Sign-On for APEX applications based on Kerberos (Important: latest ver...Single Sign-On for APEX applications based on Kerberos (Important: latest ver...
Single Sign-On for APEX applications based on Kerberos (Important: latest ver...
 

Recently uploaded

Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Albert Hoitingh
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
Frank van Harmelen
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
Product School
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
Alison B. Lowndes
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Tobias Schneck
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
BookNet Canada
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
Elena Simperl
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
Dorra BARTAGUIZ
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 

Recently uploaded (20)

Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*Neuro-symbolic is not enough, we need neuro-*semantic*
Neuro-symbolic is not enough, we need neuro-*semantic*
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
 
The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
 
Elevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object CalisthenicsElevating Tactical DDD Patterns Through Object Calisthenics
Elevating Tactical DDD Patterns Through Object Calisthenics
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 

AWS Workspaces Overview v2

  • 1. AMAZON WORKSPACES OVERVIEW By John Louis Garcia Senior AWS Architect 04/14/2020
  • 2. Introduction Amazon Workspaces is a manage secured Desktop as a Service (DaaS) desktop solution.
  • 3. Getting Started 1. You must have an AWS account to create or administer a WorkSpace. Users do not need an AWS account to connect to and use their WorkSpaces. 2. When you launch a WorkSpace, you must select a WorkSpace bundle. For more information, see Amazon WorkSpaces Bundles. 3. When you launch a WorkSpace, you must specify profile information for the user, including a user name and email address. Users complete their profiles by specifying a password. Information about WorkSpaces and users is stored in a directory. 4. Amazon WorkSpaces is not available in every Region. Verify the supported Regions and select a Region for your WorkSpaces. For more information about the supported Regions, see Amazon WorkSpaces Pricing by AWS Region.
  • 4. Options 1. Quick Setup • For an individual / small group of cloud-based users. 2. Advanced Setup • For advanced setup that includes on-premise connectivity, Microsoft AD with Amazon VPC
  • 5. Requirements A. Virtual Private Cloud (VPC) You’ll need a minimum of two subnets for a WorkSpaces deployment because each AWS Directory Service construct requires two subnets in a Multi-AZ deployment.
  • 6. Requirements B. Directory Service AD Connector — Use your existing on-premises Microsoft Active Directory. Users can sign into their WorkSpaces using their on-premises credentials and access on-premises resources from their WorkSpaces. Microsoft AD — Create a Microsoft Active Directory hosted on AWS. Simple AD — Create a directory that is compatible with Microsoft Active Directory, powered by Samba 4, and hosted on AWS. Cross trust — Create a trust relationship between your Microsoft AD directory and your on-premises domain. Amazon Cognito User Pools — With user pools, you can add user registration and sign- in features to your apps. Users can sign in with an email address, phone number, or username rather than use an external identity provider like Facebook or Google. You can also create custom registration fields and store that metadata in your user directory. You can verify email addresses and phone numbers, recover passwords, and enable multi- factor authentication (MFA) with just a few lines of code.
  • 7. Requirements C. Workspaces Client Android Client Application, iPad Client Application, Linux Client, Application, macOS Client Application, PCoIP Zero Client, Web Access, Windows Client Application
  • 8. Supported Regions AWS Service Americas Europe/Middle East/Africa Asia Pacific Amazon Workspaces Northern Virginia, Oregon, Montreal, São Paulo, AWS GovCloud (US-West) Ireland, Frankfurt, London Singapore, Tokyo, Sydney, Seoul, Ningxia* Amazon Workspace Application Manager (WAM) Northern Virginia, Oregon, Ireland Singapore, Sydney Amazon Workdocs Northern Virginia, Oregon, Ireland Singapore, Tokyo, Sydney https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/
  • 10. Workspaces Diagram 2 USERS AMAZON WORKSPACES CORPORATE DATA CENTER AWS CLOUD * SERVERS * APPLICATIONS * DATABASES
  • 11. Bundles and Images A WorkSpace bundle is a combination of an operating system, and storage, compute, and software resources. When you launch a WorkSpace, you select the bundle that meets your needs. The default bundles available for WorkSpaces are called public bundles. For more information about the various public bundles available for Amazon WorkSpaces, see Amazon WorkSpaces Bundles. If you've launched a Windows or Amazon Linux WorkSpace and have customized it, you can create a custom image from that WorkSpace. A custom image contains only the OS, software, and settings for the WorkSpace. A custom bundle is a combination of both that custom image and the hardware from which a WorkSpace can be launched. Amazon WorkSpaces offers Amazon Linux WorkSpaces built on Amazon Linux 2 LTS, or Windows 10 desktop experiences. The Windows 10 desktop experiences is powered by Windows Server 2016. If your organization is eligible to bring their own Windows Desktop licenses, you can run the Windows 10 Enterprise operating system on your Amazon WorkSpaces.
  • 13. Workspaces Application Manager (WAM) Amazon WorkSpaces Application Manager (Amazon WAM) offers a fast, flexible, and secure way for you to deploy and manage applications for Amazon WorkSpaces. Amazon WAM accelerates software deployment, upgrades, patching, and retirement by packaging Microsoft Windows desktop applications into virtualized application containers. These applications run on the end- user’s Amazon WorkSpaces instance as though they are natively installed.
  • 14. Amazon Workdocs Amazon WorkDocs is a fully managed, secure content creation, storage, and collaboration service. With Amazon WorkDocs, you can easily create, edit, and share content, and because it’s stored centrally on AWS, access it from anywhere on any device. Amazon WorkDocs makes it easy to collaborate with others, and lets you easily share content, provide rich feedback, and collaboratively edit documents. You can use Amazon WorkDocs to retire legacy file share infrastructure by moving file shares to the cloud. Amazon WorkDocs lets you integrate with your existing systems and offers a rich API so that you can develop your own content-rich applications. Amazon WorkDocs is built on AWS, where your content is secured on the world's largest cloud infrastructure.
  • 15. Launching a workspace 1. Workspace Administrator will launch the workspace. Administrator will select the directory, create the user and add it to directory. Select the bundle and configure the workspace. Choose the running mode (always on / autostop). Select encryption. 2. User will receive a verification email that will require the user to click on a provided URL. The email will contain a registration code. 3. User will require a change of password. 4. User will use the registration when logging in from the workspace client. 5. User will need to download from https://clients.amazonworkspaces.com/ and install the workspace client.
  • 16. Workspace Limits By default, a single AWS account can have a maximum of 5 WorkSpaces per region. The following information must be included in the "Use case description" if the limit increase request is for more than 200 WorkSpaces or more than 20 Graphics/GraphicsPro WorkSpaces: Is this request for Coronavirus Disease 2019 (COVID-19) DR/BR planning purposes, or for a planned rollout/scale up? What percentage of your overall user base does this request cover? What percentage of your users do you expect to use WorkSpaces if you have alternative method to have users connect to your network such as VPN? What percentage of your WorkSpaces will be using Always On running mode? What percentage of your WorkSpaces will be using AutoStop running mode? What bundle type(s) are you planning to use (Value, Standard, Performance, Power, PowerPro, Graphics, GraphicsPro)? If more than one type, please add approximate percentage for each. What is the target date/date range to ramp up to these WorkSpaces? Will you deploy them in batches or on demand if user requests? Do you plan on using BYOL (dedicated hardware) WorkSpaces?
  • 18. Tips 1. The following ports needs to be allowed in your firewall. • Web Browser (HTTPS 443) • Application Client (TCP and UDP 4175) 2. A minimum of 1 Mbps per simultaneous user watching a 480p video window. 3. When designing a VPC, always think about the future scenarios. Design a network that has enough IP Ranges for your requirements for you cannot rebuild this later. 4. When choosing a Directory Service, always think about the future scenarios. If you are resolving your DNS from an Active Directory trust, don’t use Simple AD. 5. If you need to check which Region has the best latency from your location, go to https://clients.amazonworkspaces.com/Health.html. 6. When you use the Workspace Application Manager (WAM) and you can’t see the shortcut icon from your workspace desktop, reboot your workspace. If not open command prompt and do the following. c: cd C:Program FilesAmazon WorkSpacesApplicationManager.exe 7. If you can’t see any applications in your WAM Application Client, go to APPS then choose DISCOVER. 8. Always be mindful on the supported regions.
  • 19. Tips 9. Each WorkSpace is assigned to a single user and cannot be shared by multiple users. 10. By default, web access (browser) is disabled. To enable, go to directories, click on the dropdown and select update details. Click on the Access Control Option and select “web access” on the list. 11. Workspace can also include Microsoft Office 2010, 2013, 2016. It comes with an additional cost. 12. You can build your own applications on WAM. 13. You can create group policies on your Microsoft Active Directory. 14. If you want to build your own catalog (apps) and use them in WAM, you will need to build WAM Servers (WAM Player and WAM Studio). These servers doesn’t need to be hosted inside your workspace VPC. You can deploy this to any VPC as long as it has an internet connection. 15. You can reset your user password by going to the aws directory services. Select your directory and click reset user password. 16. You can also connect to the workspace via RDP as long the security groups allows it and the workspace has access to the internet. Once connected, you will also need to authenticate to login. 17. You can restrict access only for trusted devices. You will need to create the certificates, deploy the client cert to your trusted device and configure your setting from the AWS dashboard (Directories then Access Control Options). https://docs.aws.amazon.com/workspaces/latest/adminguide/trusted-devices.html
  • 20. Links Amazon Workspaces Documentation https://docs.aws.amazon.com/workspaces/index.html User Guide https://docs.aws.amazon.com/workspaces/latest/userguide/workspaces-ug.pdf Best Practices https://d1.awsstatic.com/whitepapers/workspaces/Best_Practices_for_Deploying_Ama zon_WorkSpaces.pdf Multi Factor Authentication https://docs.aws.amazon.com/workspaces/latest/adminguide/update-directory- details.html#connect-mfa FAQ https://aws.amazon.com/workspaces/faqs/