Elastic Desktop Service (EDS) Enterprise supports both convenience accounts and enterprise Active Directory (AD) accounts. When you create an office network, you can base it on either account type. This topic describes how to create and manage an office network based on enterprise AD accounts.
Billing
An AD-based office network connects to your enterprise AD through an AD Connector. AD Connector is billed on a pay-as-you-go basis. The fee is determined by the usage duration and unit price, which varies by specification. For more information, see AD Connector pricing.
To stop billing, delete the office network. For more information, see Delete an office network.
Prerequisites
Before you begin, ensure that you have:
An enterprise AD environment. If the AD domain controller and DNS server are deployed on different servers, make sure that the DNS on the AD domain controller points to the IP address of the DNS server.
A Cloud Enterprise Network (CEN) instance, with both the enterprise AD VPC and the office network VPC associated with the same CEN instance. For more information, see Create a CEN instance.
NoteIf the AD domain controller and DNS server are deployed in an on-premises data center, connect the on-premises network to Alibaba Cloud by using Express Connect, VPN Gateway, or Smart Access Gateway (SAG). For more information, see Select a private network service
The required network ports opened. The office network VPC must access the following ports on the AD domain controller. Make sure that these ports are allowed in the firewall, security group, or security software on the AD domain controller and DNS server.
Protocol type
Port or port range
Description
Authorized object
Custom UDP
53
DNS
Office network IPv4 CIDR block, for example, 192.168.XX.XX/24
88
Kerberos
123
Windows Time
137
NETBIOS
138
NETBIOS
389
LDAP
445
CIFS
464
Kerberos password change/reset
Custom TCP
53
DNS
Office network IPv4 CIDR block, for example, 192.168.XX.XX/24
88
Kerberos
135
Replication
389
LDAP
443
HTTPS
445
SMB/CIFS
636
LDAP SSL
9389
PowerShell
49152–65535
RPC
3268–3269
LDAP GC and LDAP GC SSL
Create an office network
-
Log on to the Elastic Desktop Service Enterprise console.
-
In the left-side navigation pane, choose .
-
In the top navigation bar, select a region.
On the Office Networks page, click Create Office Network.
In the Create Office Network panel, select Advanced Office Network, complete the other configurations, and click Next: Configure Account System.
In the Configure Account System step, select Enterprise AD Account in the Account Type area, configure the following parameters, then click OK.
In the Create Office Network panel, click Close. On the Office Networks page, check the Status column:
If the status is Configure users, the office network is created successfully. Click the office network ID, then in the Basic Information section, click Configure next to Status to complete user configuration.
If the status is Configure the domain information, check and correct the Account Type settings, the network connection between the office network and the DNS server, and the security group rules of the DNS server. Then, on the office network details page, click Retry to re-create the office network. For more information, see FAQ about AD office networks.
Configure users
-
In the left-side navigation pane, choose .
-
In the top navigation bar, select a region.
On the Office Networks page, click the office network ID of the target office network.
On the office network details page, perform one of the following actions:
In the Basic Information area, click Configure next to Status.
In the Account Type area, click Configure next to Domain Username.
In the Configure AD Domain panel, enter the domain username and password, confirm the password, then click Verify.The domain user must have permissions to join computers to the AD domain and read user attributes, so that cloud desktops in this office network can be added to the AD domain server and assigned to users.
NoteThe domain user must have permissions to join computers to the AD domain and read user attributes, so that cloud computers in this office network can be added to the AD domain server and assigned to users.
After verification succeeds, in the Account Type area, click Edit next to OU, then select an OU from the OU drop-down list.
After configuration, the office network status changes to Registered. You can now create cloud computers or cloud computer shares in this office network.
Modify domain controller settings
After an AD office network is created, if the domain controller address changes, you can update the domain controller hostname and DNS address.
-
In the left-side navigation pane, choose .
-
In the top navigation bar, select a region.
On the Office Networks page, click the office network ID of the target office network.
In the AD Configuration section, click Edit next to Domain Controller Hostname/DNS Address, enter the new hostname and DNS address, then click OK.
NoteIf the modification fails, the domain controller hostname and DNS address revert to their previous values.
Set cloud computer local administrators
A local administrator can install software and perform tasks that require local administrator privileges. You can enable local administrators when creating the office network, or configure them in the AD domain controller.
Method | Advantage | Disadvantage |
Set during office network creation | Simple one-time setup. All authorized users in the AD office network become local administrators. | Applies at the office network level. All cloud computers in the office network have local administrator privileges. Not granular. |
Set in the AD domain controller | Granular control. Assign local administrator privileges to specific users as needed. | Requires manual configuration in the AD domain controller. More steps involved. |
For information about how to set local administrators in the AD domain controller, see How do I set local administrators in an AD domain?
Manage an office network
After creating the office network, you can perform the following common management tasks:
Delete an office network
You must release all cloud computer resources in the office network before you can delete it. After you delete an AD-based office network, AD Connector billing stops.
Before deleting an office network, make sure that all important resources and data in the office network have been backed up. Deleted resources and data cannot be recovered.
-
In the left-side navigation pane, choose .
-
In the top navigation bar, select a region.
On the Office Networks page, find the target office network, then click Delete in the Actions column.
In the confirmation dialog box, read the prompt and click OK.
Next steps
After creating the office network, you can: