View a markdown version of this page

Security pillar - AWS Prescriptive Guidance

Security pillar

The security pillar focuses on protecting information and systems. The following recommendations can help you meet the security design principles and architectural best practices for AWS Managed Microsoft AD.

Key focus areas

  • Data integrity and confidentiality

  • Managing user permissions

  • Establishing controls to detect security events

Implement a strong identity foundation

  • Grant the least AWS Identity and Access Management (IAM) privileges needed to AWS resources that must integrate with AWS Managed Microsoft AD.

  • Grant the least Microsoft Active Directory security permissions needed for the users and groups that you create within Microsoft Active Directory. 

  • Use group Managed Service Accounts (gMSAs) together with Kerberos constrained delegation to manage service accounts. Make sure that you specify and enforce application trust boundaries by limiting when application services can act on a user's behalf.

Activate traceability

Apply security to all layers

Automate security best practices and prepare for security events

Protect data in transit and at rest

  • Activate server-side and client-side secure Lightweight Directory Access Protocol (LDAP). For more information, see Enable secure LDAP (LDAPS) in the AWS Directory Service documentation.