All Products
Search
Document Center

Elastic Desktop Service:Attach and detach an office network from a CEN instance

Last Updated:Apr 09, 2026

To establish private communication between different Elastic Desktop Service office networks, or between an office network and other resources such as an on-premises data center (IDC) or another Virtual Private Cloud (VPC), you can attach the office network to a Cloud Enterprise Network (CEN) instance to enable network communication. This topic describes how to attach an office network to and detach it from a Cloud Enterprise Network instance.

Prerequisites

  • Network type: Only advanced office networks can be attached to or detached from a CEN instance.

  • Instance attachment limits:

    • An advanced office network can be attached to only one CEN instance.

    • When you create an enterprise AD office network, you must specify a CEN instance. After the office network is created, you cannot detach it or switch to another CEN instance. This action is irreversible. Complete your network planning before you create the office network.

Attach an office network to a CEN instance

  1. Log on to the Elastic Desktop Service Enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage > Office Networks.

  3. In the top navigation bar, select a region.

  4. On the Office Network page, find the office network to attach to a Cloud Enterprise Network instance, and in the Actions column, click Attach to CEN Instance.

  5. In the Attach to CEN Instance dialog box, select same-account or cross-account depending on which Alibaba Cloud account owns the CEN instance.

    • Same-account: The office network and the CEN instance belong to the same Alibaba Cloud account. You can select the instance directly from the drop-down list.

    • Cross-account: The office network and the CEN instance belong to different Alibaba Cloud accounts. You must enter the account UID and CEN instance ID of the other account and complete identity verification.

    Note

    After you select a CEN instance, click Check. The system automatically checks for conflicts between the CIDR block of the office network and the existing routes in the selected CEN instance. If a conflict is detected, you must either modify the CIDR block of the office network or select a CEN instance that does not have CIDR block conflicts.

  6. Click OK.

    After you attach the office network to the Cloud Enterprise Network instance, the VPC of the office network can communicate with other network instances, such as other VPCs, within the Cloud Enterprise Network instance. However, security group policies govern cloud desktops. By default, only outbound access from cloud desktops is allowed, while inbound access is denied. To allow access to the cloud desktops, add inbound security group rules. For more information, see Manage security groups.

Detach from a Cloud Enterprise Network

Important

Detaching the office network immediately interrupts network communication between the office network and other network instances, such as VPCs and IDCs, within the CEN instance. This may cause service disruptions. Before you proceed, fully assess the potential impact and create a service notification or migration plan.

  1. In the left-side navigation pane, choose Networks & Storage > Office Networks.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, find the office network to detach from the Cloud Enterprise Network instance, and in the Actions column, click Detach from CEN Instance.

Billing

Using Cloud Enterprise Network to enable network communication incurs fees that vary based on the regions of the network instances.

  • Same-region network communication: When you attach network instances located in the same region to a CEN instance for private communication, you incur a connection fee and a traffic processing fee.

  • Cross-region network communication: When you attach network instances located in different regions to a CEN instance for private communication, you incur a connection fee, a traffic processing fee, and a cross-region bandwidth fee.

For more information, see CEN Billing.