EDS supports convenience accounts and enterprise AD accounts. When you create an office network (formerly workspace), you can choose either account type. This topic describes how to create and manage an office network with convenience accounts.
Create a basic office network
basic office network requires minimal configuration and is ready to use out of the box. If you want to try EDS or need no more than 50 cloud computers, create a basic office network. For the differences between basic office network and advanced office network, see Office network types.
Log on to the EDS enterprise console.
-
In the left-side navigation pane, choose Networks & Storage>Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click Create Office Network.
-
In the Create Office Network panel, select a region, enter a custom name, select Basic Office Network, and then click OK.
Create an advanced office network
advanced office network offers advanced configuration options and richer features. Create an advanced office network if you need more than 50 cloud computers or have specific configuration requirements.
Log on to the EDS enterprise console.
-
In the left-side navigation pane, choose Networks & Storage>Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click Create Office Network.
-
In the Create Office Network panel, select Advanced Office Network, configure the remaining settings, and then click Next: Configure Account System.
-
In the Configure Account System step, in the Account Type section, select Convenience Account, and then click OK.
Enable network connectivity between cloud computers in an office network
Cloud computers within the same office network can't access each other by default. To enable network connectivity, turn on the Interconnectivity toggle on the office network details page.
-
In the left-side navigation pane, choose Networks & Storage>Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click the office network ID of the target office network.
-
In the Network Information section on the office network details page, turn on the Interconnectivity toggle.
Control Internet access for cloud computers
By default, cloud computers can access the Internet through the complimentary basic bandwidth included with the office network. Use toggles and allowlists to control Internet access for cloud computers.
-
In the left-side navigation pane, choose Networks & Storage>Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click the office network ID of the target office network.
-
In the Public Bandwidth section on the office network details page, select an Internet Access Control policy:
-
Select Allow all cloud computers to access the Internet. You can configure a list of cloud computers that are not allowed to access the Internet.. To add exceptions, click Add and select the cloud computers to exclude.
-
Select Do not allow access to the Internet. You can configure a list of cloud computers that are allowed to access the Internet.. To add exceptions, click Add and select the cloud computers to exclude.
-
Configure sign-in methods and security verification for end users
To enhance sign-in security, enable Single Sign-On (SSO) or other security verification methods for end users.
-
In the left-side navigation pane, choose Networks & Storage>Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, click the office network ID of the target office network.
-
At the bottom of the office network details page, in the Other Information section, turn on or off the following toggles as needed:
-
SSO: When enabled, configure trust between the Identity Provider (IdP), such as AD FS linked to your enterprise AD, and the Service Provider (SP), such as EDS. After configuration, end users can sign in to the client by authenticating only with the IdP credentials. For more information, see Overview.
-
MFA device verification: When enabled, end users who sign in using the office network ID (formerly workspace ID) to the client must provide a dynamic verification code generated by a virtual MFA device, in addition to the username and password. For more information, see Configure multi-factor authentication (MFA).
-
Trusted device verification: When enabled, end users who sign in from a new device must pass a verification code check before access is granted.
NoteMFA device verification, SSO, and client sign-in verification are mutually exclusive. Only one security setting can be enabled at a time for each office network.
-
Unlock an office network
A convenience-account-based office network is automatically locked if no cloud computers are created within 15 consecutive days. When locked, VPC-related resources are released. To resume use, unlock the office network by following these steps.
An office network is never locked if either of the following conditions is met:
-
The network is attached to a Cloud Enterprise Network instance.
-
VPC-based private network access is configured.
-
In the left-side navigation pane, choose Networks & Storage>Office Network.
In the top navigation bar, select a region.
-
On the Office Network page, find the target office network and click Unlock in the Status column.
-
In the confirmation dialog box, click OK.
What's next
After you create an office network, you can perform the following operations:
FAQ
No verification code received when selecting a cross-account CEN instance
This issue may occur if the relevant notification channels aren't enabled or if the contact information is incorrect. Follow these steps to verify the notification settings and contact information.
Log on to the EDS enterprise console.
-
In the top navigation bar, click the
icon to open Message Center. -
In the left-side navigation pane, choose Message Reception Management>Basic Reception Management.
-
On the Basic Reception Management page, verify that the notification channels for Product creation and activation notifications are selected and confirm the contact information.