Elastic Desktop Service (EDS) Enterprise supports convenience and enterprise Active Directory (AD) accounts for office network (formerly workspace) authentication. Create and manage an office network that uses enterprise AD accounts, including AD Connector configuration and user setup.
Billing
An office network based on enterprise AD accounts connects to your enterprise AD through an AD Connector. AD Connector is billed on a pay-as-you-go basis by usage duration and specification. For details, see AD Connector pricing.
To stop billing, you must delete the office network.
Prerequisites
-
An enterprise AD environment is available. If your AD domain controller and DNS server are on separate servers, the AD domain controller DNS settings must point to the DNS server IP address.
-
You have created a Cloud Enterprise Network instance, and attached the VPC containing your enterprise AD and the office network VPC to the same Cloud Enterprise Network instance. To create a Cloud Enterprise Network instance, see Create a Cloud Enterprise Network instance.
NoteIf your AD domain controller and DNS server are deployed in your on-premises data center (IDC), you must first connect your on-premises network to the cloud through a product such as Express Connect, Smart Access Gateway (SAG), or VPN Gateway. For details, see How do I select a private connectivity product?.
-
The required network ports are open. The office network VPC must reach the following ports on the AD domain controller. Open these ports in the security group rules or firewall of your AD domain controller and DNS server.
Protocol
Port or port range
Description
Source
Custom UDP
53
DNS
The IPv4 CIDR block of the office network, e.g., 192.168.XX.XX/24.
88
Kerberos
123
Windows Time
137
NETBIOS
138
NETBIOS
389
LDAP
445
CIFS
464
Kerberos password change or reset
Custom TCP
53
DNS
The IPv4 CIDR block of the office network, e.g., 192.168.XX.XX/24.
88
Kerberos
135
Replication
389
LDAP
443
HTTPS
445
SMB/CIFS
636
LDAP SSL
9389
PowerShell
49152–65535
RPC
3268–3269
LDAP GC and LDAP GC SSL
Create an office network
Log on to the EDS enterprise console.
-
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click Create Office Network.
-
In the Create Office Network panel, select Advanced Office Network, complete the other configurations, and then click Next: Configure Account System.
-
In the Account Type section, select Enterprise AD Account, configure the following parameters, and then click OK.
-
In the Create Office Network panel, click Enable, and then on the Office Network page, check the Status column for the office network:
-
If the status is Configure users., the office network was created successfully. Click the Office network ID. On the office network details page, in the AD section, click Configure next to Status and complete the user configuration.
-
If the status is Configure the domain information., check and modify the Account Type settings, the network connection between the office network and the DNS server, and the security group rules of the DNS server. Then, on the office network details page, click Retry. to recreate the office network. For details, see FAQ about AD-based office networks.
-
Configure users
-
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click the office network ID of the target office network.
-
On the office network details page, perform one of the following actions:
-
In the Basic Information section, click Configure next to Status.
-
In the Account Type section, click Configure next to Domain User.
-
-
In the AD panel, enter the domain username and password, confirm the password, and then click Verify.
NoteThe domain user must have permissions to join computers to the AD domain and read user attributes. These permissions enable the system to join cloud computers in this office network to the AD domain and assign cloud computers to users.
-
After verification succeeds, in the Account Type section, click Edit next to OU, and select an organizational unit (OU) from the OU drop-down list.
The status of the office network changes to Registered. You can now create cloud computers or a cloud computer share in this office network.
Modify domain controller
If your domain controller address changes, update the domain controller hostname and DNS address for your AD-based office network.
-
In the left-side navigation pane, choose Networks & Storage > Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click the office network ID of the target office network.
-
In the AD section, click Edit next to Domain Controller Hostname/DNS Address, enter the new domain controller hostname and DNS address, and then click OK.
NoteIf the modification fails, the domain controller hostname and DNS address revert to their previous settings.
Set local administrators
A cloud computer local administrator can install software and perform other tasks requiring local administrator permissions. Enable local administrators during office network creation or configure them on the AD domain controller.
|
Method |
Pros |
Cons |
|
Set during office network creation |
Simple, one-time setup. All authorized users in the AD-based office network become local administrators. |
No granular control. All authorized users get local administrator permissions for all cloud computers in the office network. |
|
Set on the AD domain controller |
Granular control. Grant local administrator permissions to specific users as needed. |
Requires manual AD domain controller configuration. |
To configure local administrators on the AD domain controller, see How do I set local administrators in an AD domain?
Manage the office network
Common tasks for your office network: