All Products
Search
Document Center

Elastic Desktop Service:CreateADConnectorOfficeSite

Last Updated:Aug 10, 2026

Creates an office network (formerly workspace) based on an enterprise Active Directory (AD) account system. Elastic Desktop Service supports convenient accounts and enterprise AD accounts.

Operation description

When you create an AD office network, the system performs automatic creation of an AD Connector to connect to your enterprise AD. You are charged for the AD Connector. For more information, see Billing overview.

After you call this operation to create an AD office network, you must complete the AD domain configurations. The procedure is as follows:

  1. Configure a conditional forwarder on the DNS server.

  2. Configure a trust relationship on the AD domain server, and then call ConfigADConnectorTrust to configure the trust relationship for the AD office network.

  3. Call ListUserAdOrganizationUnits to obtain the organizational unit (OU) information of the AD domain, and then call ConfigADConnectorUser to specify the OU and administrator for the AD office network.

    Note

    When you create an AD office network, if you specify the domain administrator and password (DomainUserName and DomainPassword), you only need to configure the conditional forwarder afterward. If you do not specify the domain administrator and password, you must complete the configurations of the conditional forwarder, trust relationship, and OU as described above.

For more information, see Create and manage an AD-based office network.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

ecd:CreateADConnectorOfficeSite

create

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID. You can call DescribeRegions to query the regions supported by Elastic Desktop Service.

cn-hangzhou

CidrBlock

string

No

The IPv4 CIDR block of the office network VPC. The system uses automatic creation to provision a VPC based on the specified IPv4 CIDR block. Use one of the following CIDR blocks or their subnets as the IPv4 CIDR block:

  • 10.0.0.0/12 (valid mask range: 12 to 24 bits)

  • 172.16.0.0/12 (valid mask range: 12 to 24 bits)

  • 192.168.0.0/16 (valid mask range: 16 to 24 bits)

47.100.XX.XX

CenOwnerId

integer

No

The Alibaba Cloud account ID of the Cloud Enterprise Network (CEN) instance owner.

  • If CenId is not specified, or the specified CenId belongs to the current Alibaba Cloud account, you do not need to specify this parameter.

  • If the specified CenId belongs to another Alibaba Cloud account, specify the Alibaba Cloud account ID of that account.

102681951715****

CenId

string

No

The instance ID of the Cloud Enterprise Network (CEN).

cen-3gwy16dojz1m65****

VerifyCode

string

No

The verification code. If the specified CenId belongs to another Alibaba Cloud account, you must first call SendVerifyCode to obtain the verification code.

12****

Bandwidth

integer

No

The peak Internet bandwidth, in Mbit/s. Valid values: 0 to 200.
If you do not set this parameter or set it to 0, the Internet access feature is not enabled. Settings take effect immediately.

1

DomainName

string

Yes

The domain name of the enterprise AD. The same domain name can be registered only once.

example.com

DomainUserName

string

No

The username of the domain administrator. The username can be up to 64 characters in length.

Note

Use the sAMAccountName format for the username. Do not use the userPrincipalName format.

Administrator

DomainPassword

string

No

The password of the domain administrator. The password can be up to 64 characters in length.

testPassword

OfficeSiteName

string

No

The name of the office network. The name must be 2 to 255 characters in length and can contain letters, digits, colons (:), underscores (_), and hyphens (-). The name must start with a letter or Chinese character and cannot start with http:// or https://.
Default value: null.

RD_Office_Network

EnableAdminAccess

boolean

No

Specifies whether to grant local administrator permissions to users who use cloud computers.

Valid values:

  • true :

    Grants local administrator permissions. [Default]

  • false :

    Does not grant local administrator permissions.

true

DesktopAccessType

string

No

The access method allowed when connecting to cloud computers.

Note

The VPC connection method depends on the Alibaba Cloud PrivateLink service, which is free of charge. If this parameter is set to VPC or Any, the system automatically activates the PrivateLink service for you.

Valid values:

  • VPC :

    Only allows clients within a VPC to connect to cloud computers.

  • Internet :

    Only allows clients to connect to cloud computers over a public network connection. [Default]

  • Any :

    No restriction. Users can choose the connection method when using a client to connect to cloud computers.

Internet

EnableInternetAccess

boolean

No

Specifies whether public network access is enabled. This parameter indicates whether the feature is active.

true

SubDomainName

string

No

The domain name of the enterprise AD subdomain.

child.example.com

MfaEnabled

boolean

No

Specifies whether to enable multi-factor authentication (MFA).

false

DnsAddress

array

Yes

The IP address of the DNS server corresponding to the enterprise AD. Currently, only one IP address is supported.

192.168.XX.XX

string

No

The IP address of the DNS server corresponding to the enterprise AD. Currently, only one IP address is supported.

192.168.XX.XX

SubDomainDnsAddress

array

No

The DNS address of the enterprise AD subdomain. If SubDomainName is specified but this parameter is not, the subdomain DNS is considered the same as the parent domain DNS.

192.168.XX.XX

string

No

The DNS address of the enterprise AD subdomain. If SubDomainName is specified but this parameter is not, the subdomain DNS is considered the same as the parent domain DNS.

192.168.XX.XX

Specification

integer

No

The AD Connector specification.

Valid values:

  • 1 :

    General-purpose.

  • 2 :

    Advanced.

1

AdHostname

string

No

The hostname of the domain controller. The hostname must comply with Windows hostname naming conventions.

beijing-ad01

ProtocolType

string

No

The protocol type.

Valid values:

  • ASP :

    ASP protocol.

ASP

BackupDns

string

No

The DNS address of the backup domain controller.

192.168.2.100

BackupDCHostname

string

No

The hostname of the backup domain controller.

dc002

VSwitchId

array

No

The list of vSwitch IDs.

string

No

The vSwitch ID.

vsw-uf68bgq7rjwbqpg0****

AccessAttribute

string

No

The access attribute of the office network (workspace).

Private

Response elements

Element

Type

Description

Example

object

The response object.

RequestId

string

The request ID.

1CBAFFAB-B697-4049-A9B1-67E1FC5F****

OfficeSiteId

string

The office network ID.

cn-hangzhou+dir-363353****

Examples

Success response

JSON format

{
  "RequestId": "1CBAFFAB-B697-4049-A9B1-67E1FC5F****",
  "OfficeSiteId": "cn-hangzhou+dir-363353****"
}

Error codes

HTTP status code

Error code

Error message

Description

400 NetworkSpace.VpcInfoExist vpc info already exist. Office network already exists for the corresponding VPC

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.