All Products
Search
Document Center

Elastic Desktop Service:Create and manage office networks with convenience accounts

Last Updated:Jul 14, 2026

EDS supports convenience accounts and enterprise AD accounts. When you create an office network (formerly workspace), you can choose either account type. This topic describes how to create and manage an office network with convenience accounts.

Create a basic office network

basic office network requires minimal configuration and is ready to use out of the box. If you want to try EDS or need no more than 50 cloud computers, create a basic office network. For the differences between basic office network and advanced office network, see Office network types.

  1. Log on to the EDS enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage>Office Network.

  3. In the top navigation bar, select a region.

  4. On the Office Network page, click Create Office Network.

  5. In the Create Office Network panel, select a region, enter a custom name, select Basic Office Network, and then click OK.

Create an advanced office network

advanced office network offers advanced configuration options and richer features. Create an advanced office network if you need more than 50 cloud computers or have specific configuration requirements.

  1. Log on to the EDS enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage>Office Network.

  3. In the top navigation bar, select a region.

  4. On the Office Network page, click Create Office Network.

  5. In the Create Office Network panel, select Advanced Office Network, configure the remaining settings, and then click Next: Configure Account System.

    Parameter description

    Parameter

    Description

    Select Region

    The region of the office network. For supported regions and related limits, see Available regions.

    Office Network Name

    A name that identifies the office network for quick lookup.

    IPv4 CIDR Block

    When you create a cloud computer in an office network, the system automatically assigns an IP address from the office network VPC CIDR block. The number of available IP addresses determines the maximum number of cloud computers the network can hold. Plan the CIDR block accordingly. For more information, see Plan CIDR blocks.

    By default, the office network VPC supports the following IPv4 CIDR blocks and their subnets:

    • 192.168.0.0/16

    • 10.0.0.0/12

    • 172.16.0.0/12

    Connection Method

    Specifies how end users connect to cloud computers in the office network. The following options are available:

    • Internet: allows connections over the Internet only (default). The local device that runs the cloud computer must have Internet access.

    • VPC: allows connections over a VPC only. To use this option, attach the office network to a Cloud Enterprise Network (CEN) instance and connect your on-premises network to the cloud through Express Connect (leased line), Smart Access Gateway (SAG), or VPN Gateway. For more information, see Attach and detach an office network from a CEN instance, Connect a VPC to a data center or another cloud.

    • Internet and VPC: supports both connection methods.

    Note

    VPC connections rely on Alibaba Cloud PrivateLink, which is free of charge. When you select VPC or Internet and VPC, the system automatically activates PrivateLink for you.

    Attach to CEN

    To use VPC connections, select Yes. Select a Cloud Enterprise Network instance ID from the same account or a different account.

    Note

    If your on-premises network connects to the cloud through Smart Access Gateway, Express Connect (leased line), or VPN Gateway, the office network must join the same Cloud Enterprise Network instance.

    To make sure that cloud computers in the office network work properly, click Check after you select the Cloud Enterprise Network instance ID. This validates whether the routes of the selected Cloud Enterprise Network instance conflict with the office network IPv4 CIDR block. If the validation fails, click View Conflict Details and Recommended CIDR Blocks and reconfigure the IPv4 CIDR block or CEN instance based on the suggestions.

  6. In the Configure Account System step, in the Account Type section, select Convenience Account, and then click OK.

Enable network connectivity between cloud computers in an office network

Cloud computers within the same office network can't access each other by default. To enable network connectivity, turn on the Interconnectivity toggle on the office network details page.

  1. In the left-side navigation pane, choose Networks & Storage>Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, click the office network ID of the target office network.

  4. In the Network Information section on the office network details page, turn on the Interconnectivity toggle.

Bind premium bandwidth plan

Each office network includes a complimentary basic bandwidth with a peak of 5 Mbps. If you need higher bandwidth, subscribe to a paid premium bandwidth plan. For billing details, see Billable items.

  1. In the left-side navigation pane, choose Networks & Storage>Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, click the office network ID of the target office network.

  4. In the Public Bandwidth section on the office network details page, click Associate.

  5. In the Associate dialog box, select a premium bandwidth plan. If no options are available, click Buy Premium Bandwidth Plan to purchase one.

Control Internet access for cloud computers

By default, cloud computers can access the Internet through the complimentary basic bandwidth included with the office network. Use toggles and allowlists to control Internet access for cloud computers.

  1. In the left-side navigation pane, choose Networks & Storage>Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, click the office network ID of the target office network.

  4. In the Public Bandwidth section on the office network details page, select an Internet Access Control policy:

    • Select Allow all cloud computers to access the Internet. You can configure a list of cloud computers that are not allowed to access the Internet.. To add exceptions, click Add and select the cloud computers to exclude.

    • Select Do not allow access to the Internet. You can configure a list of cloud computers that are allowed to access the Internet.. To add exceptions, click Add and select the cloud computers to exclude.

Configure sign-in methods and security verification for end users

To enhance sign-in security, enable Single Sign-On (SSO) or other security verification methods for end users.

  1. In the left-side navigation pane, choose Networks & Storage>Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, click the office network ID of the target office network.

  4. At the bottom of the office network details page, in the Other Information section, turn on or off the following toggles as needed:

    • SSO: When enabled, configure trust between the Identity Provider (IdP), such as AD FS linked to your enterprise AD, and the Service Provider (SP), such as EDS. After configuration, end users can sign in to the client by authenticating only with the IdP credentials. For more information, see Overview.

    • MFA device verification: When enabled, end users who sign in using the office network ID (formerly workspace ID) to the client must provide a dynamic verification code generated by a virtual MFA device, in addition to the username and password. For more information, see Configure multi-factor authentication (MFA).

    • Trusted device verification: When enabled, end users who sign in from a new device must pass a verification code check before access is granted.

    Note

    MFA device verification, SSO, and client sign-in verification are mutually exclusive. Only one security setting can be enabled at a time for each office network.

Unlock an office network

A convenience-account-based office network is automatically locked if no cloud computers are created within 15 consecutive days. When locked, VPC-related resources are released. To resume use, unlock the office network by following these steps.

Note

An office network is never locked if either of the following conditions is met:

  • The network is attached to a Cloud Enterprise Network instance.

  • VPC-based private network access is configured.

  1. In the left-side navigation pane, choose Networks & Storage>Office Network.

  2. In the top navigation bar, select a region.

  3. On the Office Network page, find the target office network and click Unlock in the Status column.

  4. In the confirmation dialog box, click OK.

What's next

After you create an office network, you can perform the following operations:

FAQ

No verification code received when selecting a cross-account CEN instance

This issue may occur if the relevant notification channels aren't enabled or if the contact information is incorrect. Follow these steps to verify the notification settings and contact information.

  1. Log on to the EDS enterprise console.

  2. In the top navigation bar, click the Notification icon to open Message Center.

  3. In the left-side navigation pane, choose Message Reception Management>Basic Reception Management.

  4. On the Basic Reception Management page, verify that the notification channels for Product creation and activation notifications are selected and confirm the contact information.