All Products
Search
Document Center

Elastic Desktop Service:Create and manage an AD-based office network

Last Updated:Jun 04, 2026

Elastic Desktop Service (EDS) Enterprise supports convenience and enterprise Active Directory (AD) accounts for office network (formerly workspace) authentication. Create and manage an office network that uses enterprise AD accounts, including AD Connector configuration and user setup.

Billing

An office network based on enterprise AD accounts connects to your enterprise AD through an AD Connector. AD Connector is billed on a pay-as-you-go basis by usage duration and specification. For details, see AD Connector pricing.

To stop billing, you must delete the office network.

Prerequisites

  • An enterprise AD environment is available. If your AD domain controller and DNS server are on separate servers, the AD domain controller DNS settings must point to the DNS server IP address.

  • You have created a Cloud Enterprise Network instance, and attached the VPC containing your enterprise AD and the office network VPC to the same Cloud Enterprise Network instance. To create a Cloud Enterprise Network instance, see Create a Cloud Enterprise Network instance.

    Note

    If your AD domain controller and DNS server are deployed in your on-premises data center (IDC), you must first connect your on-premises network to the cloud through a product such as Express Connect, Smart Access Gateway (SAG), or VPN Gateway. For details, see How do I select a private connectivity product?.

  • The required network ports are open. The office network VPC must reach the following ports on the AD domain controller. Open these ports in the security group rules or firewall of your AD domain controller and DNS server.

    Protocol

    Port or port range

    Description

    Source

    Custom UDP

    53

    DNS

    The IPv4 CIDR block of the office network, e.g., 192.168.XX.XX/24.

    88

    Kerberos

    123

    Windows Time

    137

    NETBIOS

    138

    NETBIOS

    389

    LDAP

    445

    CIFS

    464

    Kerberos password change or reset

    Custom TCP

    53

    DNS

    The IPv4 CIDR block of the office network, e.g., 192.168.XX.XX/24.

    88

    Kerberos

    135

    Replication

    389

    LDAP

    443

    HTTPS

    445

    SMB/CIFS

    636

    LDAP SSL

    9389

    PowerShell

    49152–65535

    RPC

    3268–3269

    LDAP GC and LDAP GC SSL

Create an office network

  1. Log on to the EDS enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage > Office Network.

  3. In the top navigation bar, select a region.

  4. On the Office Network page, click Create Office Network.

  5. In the Create Office Network panel, select Advanced Office Network, complete the other configurations, and then click Next: Configure Account System.

    Parameters

    Parameter

    Description

    Select Region

    The region of the office network. For information about the supported regions and the relevant limits, see Available regions.

    Office Network Name

    The name of the office network. Used to identify and quickly locate the office network.

    IPv4 CIDR Block

    When you create a cloud computer in the office network, the system automatically assigns an IP address from the CIDR blocks of the office network VPC as the IP address of the cloud computer. The number of IP addresses in the VPC CIDR block determines the maximum number of cloud computers that can be accommodated. Plan the CIDR blocks based on your business requirements. For more information, see Plan CIDR blocks.

    By default, you can set the office network VPC to one of the following IPv4 CIDR blocks and its subnet CIDR blocks:

    • 192.168.0.0/16

    • 10.0.0.0/12

    • 172.16.0.0/12

    Connection Method

    Specifies how cloud computer end users can connect to the cloud computers in the office network. Valid values:

    • Internet: Only Internet connections are allowed (the default option). To use this method, the local devices running the cloud computers must have access to the Internet.

    • VPC: Only Virtual Private Cloud (VPC) connections are allowed. To use this method, you must add the office network to a Cloud Enterprise Network (CEN) instance, and use products such as Express Connect (leased line), Smart Access Gateway (SAG), or VPN Gateway to connect the on-premises network with the cloud network. For more information, see Attach and detach an office network from a CEN instance and Select a private network service.

    • Internet and VPC: Both of the preceding connection methods are supported.

    Note

    VPC connections rely on the Alibaba Cloud PrivateLink service, which is free of charge. When you select VPC or Internet and VPC, the system automatically activates the PrivateLink service for you.

    Attach to CEN

    To use the VPC connection method, select Yes. You can select the ID of a Cloud Enterprise Network instance under the same account or a different account based on your business requirements.

    Note

    If the on-premises network connects to the cloud network over Smart Access Gateway, Express Connect (leased line), or VPN Gateway, the office network must be added to the same Cloud Enterprise Network instance.

    To ensure that the cloud computers in the office network work properly, after you select the Cloud Enterprise Network instance ID, click Check to check whether the routes of the selected Cloud Enterprise Network instance conflict with the IPv4 CIDR block of the office network. If the check fails, click View Conflict Details and Recommended CIDR Blocks, and reconfigure the IPv4 CIDR block or the Cloud Enterprise Network instance based on the recommendations.

  6. In the Account Type section, select Enterprise AD Account, configure the following parameters, and then click OK.

    Parameters

    Parameter

    Description

    Domain Name

    Your enterprise's AD domain name. Example: example.com.

    Domain Controller Hostname

    The hostname of your AD domain controller.

    • If your AD domain controller and DNS server are on separate devices, enter the domain controller hostname to specify which domain controller to use for office network creation.

    • If your AD domain controller and DNS server are deployed on the same device, this parameter is optional.

    DNS Address

    The DNS server IP address for your enterprise AD.

    If the AD domain controller and DNS server are on the same device, enter the AD domain controller IP address. This address must be accessible from the office network configured in the previous step.

    Secondary Domain Controller Hostname/Secondary DNS Address

    Click Add Secondary Domain Controller Hostname/DNS Address to configure a secondary Secondary Domain Controller Hostname and a secondary Secondary DNS Address.

    Ensures high availability. If one domain controller fails, you can still create cloud computers, assign them to AD accounts, and let end users sign in.

    Local Administrator

    A cloud computer local administrator can install software and perform other tasks that require local administrator permissions.

    If you select Specify AD User as Local Administrator, all users authorized to use cloud computers in the office network receive local administrator permissions.

    Alternatively, you can set local administrators on your AD domain controller. For details, see Set local administrators for cloud computers.

    AD Connector Type

    Select an AD Connector specification based on the estimated number of cloud computers:

    • Basic: For up to 50 cloud computers.

    • General: For up to 1,000 cloud computers.

    • Advanced: For more than 1,000 cloud computers.

  7. In the Create Office Network panel, click Enable, and then on the Office Network page, check the Status column for the office network:

    • If the status is Configure users., the office network was created successfully. Click the Office network ID. On the office network details page, in the AD section, click Configure next to Status and complete the user configuration.

    • If the status is Configure the domain information., check and modify the Account Type settings, the network connection between the office network and the DNS server, and the security group rules of the DNS server. Then, on the office network details page, click Retry. to recreate the office network. For details, see FAQ about AD-based office networks.

Configure users

  1. In the left-side navigation pane, choose Networks & Storage > Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, click the office network ID of the target office network.

  4. On the office network details page, perform one of the following actions:

    • In the Basic Information section, click Configure next to Status.

    • In the Account Type section, click Configure next to Domain User.

  5. In the AD panel, enter the domain username and password, confirm the password, and then click Verify.

    Note

    The domain user must have permissions to join computers to the AD domain and read user attributes. These permissions enable the system to join cloud computers in this office network to the AD domain and assign cloud computers to users.

  6. After verification succeeds, in the Account Type section, click Edit next to OU, and select an organizational unit (OU) from the OU drop-down list.

The status of the office network changes to Registered. You can now create cloud computers or a cloud computer share in this office network.

Modify domain controller

If your domain controller address changes, update the domain controller hostname and DNS address for your AD-based office network.

  1. In the left-side navigation pane, choose Networks & Storage > Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, click the office network ID of the target office network.

  4. In the AD section, click Edit next to Domain Controller Hostname/DNS Address, enter the new domain controller hostname and DNS address, and then click OK.

    Note

    If the modification fails, the domain controller hostname and DNS address revert to their previous settings.

Set local administrators

A cloud computer local administrator can install software and perform other tasks requiring local administrator permissions. Enable local administrators during office network creation or configure them on the AD domain controller.

Method

Pros

Cons

Set during office network creation

Simple, one-time setup. All authorized users in the AD-based office network become local administrators.

No granular control. All authorized users get local administrator permissions for all cloud computers in the office network.

Set on the AD domain controller

Granular control. Grant local administrator permissions to specific users as needed.

Requires manual AD domain controller configuration.

To configure local administrators on the AD domain controller, see How do I set local administrators in an AD domain?

Manage the office network

Common tasks for your office network:

Next steps