Identity modules
Identity modules create the necessary resources to allow users to interact with MCS and the post production environment.
The following Identity modules are available in MCS after deployment:
-
Managed Active Directory module - Deploys a new Microsoft Active Directory instance under standard edition
-
Unmanaged Active Directory module - Receives existing Microsoft Active Directory information from an input form
Managed Active Directory module

-
Directory Service deploys an instance of AWS Managed Microsoft AD under standard edition.
-
The Active Directory module deploys a temporary EC2 instance that:
-
Joins to the AWS Managed Microsoft AD domain
-
Sets password policy for domain users (90-day expiration)
-
Self-terminates after approximately 5 minutes
-
-
User credentials generated during deployment are automatically stored in AWS Secrets Manager.
Spoke Managed Identity module
-
Directory Service deploys an AD Connector instance that establishes a connection to the Microsoft AD instance in the Hub environment.