Performance efficiency pillar
The performance efficiency pillar focuses on structured and streamlined allocation of IT and computing resources. The following recommendations can help you meet the performance efficiency design principles and architectural best practices for AWS Managed Microsoft AD.
Key focus areas
Selecting resource types and sizes optimized for workload requirements
Monitoring performance
Maintaining efficiency as business needs evolve
Democratize advanced technologies and make their implementation easier for your team
For data that's configured and deployed through a group policy or home folders and a roaming user profile, use Amazon FSx for Windows File Server.
Scale globally if needed
Activate multi-Regional replication when there's a need for users and applications in disperse geographic regions to authenticate against AWS Managed Microsoft AD. For more information, see Lab 4 – Enable Multi-Region with AWS Managed Microsoft AD
in the Active Directory on AWS Immersion Day Workshop.
Use serverless architectures
Use serverless services, such as AWS Lambda and AWS Secrets Manager, to extend the functionalities of AWS Managed Microsoft AD. For example, serverless products can help users to reset their own passwords. They can also help you obtain temporary credentials for applications without manually provisioning them.
Test and experiment often
Test your infrastructure changes in a test environment before deploying changes to production.
Stay up to date on new resources and services and regularly test them in your test environment.
Consider mechanical sympathy
Make a backup of your instance if you decide to manually add an instance to an existing AWS Managed Microsoft AD domain.
Use Amazon CloudWatch metrics to generate alarm-based notifications for AWS Managed Microsoft AD. For more information, see Lab 5 – Create a CloudWatch alarm based on Windows event logs
in the Active Directory on AWS Immersion Day Workshop.
Improve performance
Use the Windows DC locator service or the Dynamic DNS (DDNS) service of your AWS Managed Microsoft AD to locate domain controllers (DCs). For more information, see Enabling clients to locate the next closest domain controller
in the Microsoft documentation. Use efficient LDAP queries.
Automate AWS Managed Microsoft AD scaling based on utilization metrics. For more information, see How to automate AWS Managed Microsoft AD scaling based on utilization metrics
on the AWS Blog. Load test before rolling any changes out to production.
Choose appropriately sized, dedicated connectivity or a virtual private network (VPN) when you need to establish trust relationships with an on-premises Microsoft Active Directory.