3 ms·
I tested this out just yesterday. It was fairly easy to set up - enable SSO, create a Directory Service, add a management EC2 instance, and you're pretty much u
by aynsof 9y ago
I tested this out just yesterday. It was fairly easy to set up - enable SSO, create a Directory Service, add a management EC2 instance, and you're pretty much up and running.
You've got to set up your own Active Directory using Directory Services, which is $288USD/month minimum for two domain controllers.
In order to have MFA for logging into the console (non-negotiable in my opinion), you have to configure your own RADIUS server.
And the question of how to manage access keypairs still remains unanswered, as far as I can tell.
I don't know if this is going to supplant Azure AD as our SSO method of choice.
- yeukhon 9y agoHmm how did you calculate the DC to be $288 for total of two? I believe you can use AD connector to connect to on-premise AD.
- aynsof 9y ago$288 comes from here: https://aws.amazon.com/directoryservice/pricing/ https://aws.amazon.com/directoryservice/pricing/ It looks like AD Connector is much less: https://aws.amazon.com/directoryservice/other-directories-pricing/ https://aws.amazon.com/directoryservice/other-directories-pr...
- Johnny555 9y agoI think you're looking at the Enterprise domain controller pricing. the Standard size (up to 30,000 objects) is 12 cents/hour for two controllers. $0.12 * 24 * 30 = $86.40/month.
- aynsof 9y agoYou're right! Thanks for the pick-up. I'd change the statement in my parent post, but I don't seem to be able to edit it.
- unkoman 9y agoAzure AD to AWS is quite simple: * Create an AWS Cognito User pool * Create an Azure AD Enterprise Application * Set up Azure AD federation to the Cognito User Pool