SlideShare a Scribd company logo
1 of 23
Download to read offline
Amazon WorkSpaces: Advanced Topics and Deep Dive
Justin Bradley,
AWS Solutions Architect
Agenda
1. Amazon WorkSpaces Overview
2. Amazon WorkSpaces Bundles
3. Amazon WorkSpaces Application Manager &
Marketplace for Desktop Apps
4. Amazon Directory Service- Active Directory
Integration
5. Network Considerations (Amazon Virtual Private
Cloud)
6. Amazon WorkSpaces Communiction Flows
The Work* Services
WorkDocs
Secure enterprise
document collaboration
WorkSpaces
Virtual desktops
Secure access from anywhere
Monthly pricing
Central sync, document feedback
Secure access from anywhere
S3
WorkSpaces Application
Manager (WAM)
Virtual applications
Centralized application deployment
Monthly subscription options
WorkMail
Secure email and
calendaring
Strong security controls
Existing desktop, mobile support
Directory Service
Simple AD, AD Connector
WorkSpaces: Fully Managed
• Launch the number of WorkSpaces needed
• All heavy lifting taken care of by AWS
• Users receive email to install clients and connect
WorkSpaces
Amazon WorkSpaces Devices
• iPad
• Kindle Fire HDX (Keyboard & Mouse)
• Android Tablet
• Microsoft Windows
• Mac
• Zero clients
• Cromebook
Keep Data Secure and Available
• No data stored on end-user device
• Only Pixels delivered to users (PCoIP)
• User volume backed by Amazon S3
• Multi-factor authentication (MFA)
• Encrypted Storage Volumes Using KMS
Keep Data Secure and Available
• Securely backup and sync users data
• Install on the WorkSpace and a PC or Mac
• Data is backed up to Amazon S3
• Users can access their data when they need it
WorkDocs Sync Client
WorkSpaces: Bundles
• WorkSpaces are provisioned from bundles
• 3 WorkSpaces hardware configurations
• 3 WorkSpaces images – Default, Office 2010 or
Office 2013
Instance
Type
Image (AMI)
Bundle
Value (t2.small)
Standard (t2.medium)
Performance (m3.large)
Default
Custom
No Office
Office 2010 Professional (Plus)
Office 2013 Professional (Plus)
WorkSpaces: Choose Software and Hardware
WorkSpaces Bundle Hardware Resources Applications
Value 1 vCPU, 2 GiB Memory (t2.small), 10 GB User Storage Utilities (Adobe Reader, Internet Explorer 9,
Firefox, 7-Zip, Adobe Flash)
Value Plus 1 vCPU, 2 GiB Memory (t2.small), 10 GB User Storage Microsoft Office Professional 2010, Trend
Micro Worry-Free Business Security, Utilities
(Adobe Reader, Internet Explorer 9, Firefox, 7-
Zip, Adobe Flash)
Standard 2 vCPU, 4 GiB Memory (t2.medium), 50 GB User Storage Utilities (Adobe Reader, Internet Explorer 9,
Firefox, 7-Zip, Adobe Flash)
Standard Plus 2 vCPU, 4 GiB Memory (t2.medium), 50 GB User Storage Microsoft Office Professional 2010, Trend
Micro Worry-Free Business Security, Utilities
(Adobe Reader, Internet Explorer 9, Firefox, 7-
Zip, Adobe Flash)
Performance 2 vCPU, 7.5 GiB Memory (m3.large), 100 GB User Storage Utilities (Adobe Reader, Internet Explorer 9,
Firefox, 7-Zip, Adobe Flash)
Performance Plus 2 vCPU, 7.5 GiB Memory (m3.large), 100 GB User Storage Microsoft Office Professional 2010, Trend
Micro Worry-Free Business Security, Utilities
(Adobe Reader, Internet Explorer 9, Firefox, 7-
Zip, Adobe Flash)
WorkSpaces: Install your own software
• No technical restrictions on software installation
• Manage WorkSpaces like any other desktop
• Use the tools you already use to distribute
• WorkSpaces Application Manager (WAM)
• WorkSpaces Marketplace for Desktop Apps
• Create your own bundles (Custom)
WAM: Managing Applications for your Users
Amazon WorkSpaces
Application Manager
(Amazon WAM)
Deploy and Manage Applications
Package your own applications
Upload applications where you own
the license
Subscribe from the AWS Marketplace
for Desktop Apps
Amazon WAM Benefits
WorkSpaces
Amazon
WAM
Catalog Deploy
Apps
for Desktop Apps
Applications where you already
own the license
Line of business
applications
Curate a wide range of applications
WorkSpaces: Marketplace for Desktop Apps
DEMO: WAM & Marketplace for Desktop Apps
WorkSpaces: AD Integration
• Users: Get to use existing Enterprise Credentials
• IT: WorkSpaces control like regular desktops
– Store in the OU that makes sense to you
Simple AD
Alex Hardy
(ahardy)
Emily McLane
(emclane)
Tim Nuberg
(tnuberg)
Simple AD
AD
Connector
Alex Hardy
(ahardy)
Emily McLane
(emclane)
Tim Nuberg
(tnuberg)
AD
AD Connector
• 1 user = 1 directory username = 1 WorkSpaces desktop
– Example: Alex Hardy -> ahardy -> desktop (ahardy) (Directory Instance 1)
– Users cannot have 2 or more desktops per username, per directory instance
WorkSpaces backed by..
• Ensure existing AD is reachable (via VPC)
• Create AD Connector + Directory Account
• Launch WorkSpaces users in connected domain
• This could be on-premises or in EC2
WorkSpaces: Corporate Directory Integration Steps
Customer
Corp Network
10.31.0.0/16 VPC 172.16.0.0/16
AD
Connector
ENI
ENI
VPN
Connection
Active
Directory WorkSpaces
(Eth1)
Availability Zone B
Private subnet
DC4
Corporate Network
London
DC1
VPN / Direct
Connect
Paris
DC2
Cost 50
Availability Zone A
Private subnet
DC3
Cost 10
company.local
company.local
One single identity, data center extension mode
(Rely on Active Directory Sites, Read-Only or not)
WorkSpaces: Extend customer domain
WorkSpaces: Network Considerations (VPC)
• directory : a Directory Service instance
• 1 directory spans exactly two subnets
• 1 directory = 2 EC2 instances (1 per subnet)
• You can have multiple directories in 1 VPC
• Each directory has its own registration code
• Zero clients: each regcode needs its own url
Subnet A (AZ 1) Subnet B (AZ 2)
regcode
(example: WSpdx+A1B2C3)
zero client url
(example: https://url1.company.com)
Visualization of a Directory Instance
laptops, desktops, tablets
zero clients
WorkSpaces: Network Considerations (VPC)
• VPC Subnet Size
– AWS Fact: Largest VPC size: /16 (65K addresses)
• WorkSpaces reside in subnets as defined for Directory Connector
• Each Subnet – 6 IP’s
• Regional proximity to users
• Tie into global network via Direct Connect
• Use Existing IP space
• Restrict corporate network access when necessary
Auth/Session
Gateways
Public
AWS
Endpoint
WorkSpaces
(network entry point)
Customer VPC
EC2
WorkSpaces: Communication Flow
Active
Directory
corp
servers
Direct Connect
or VPN
Customer
Corp Net
Users
Customer
Internet
AD
Connector
Public
AWS
Endpoint
Streaming
Gateway
7
1
2
3
45
6a
6b
8
9
WorkSpaces
auth/session (SSL)
WorkSpaces
streaming (PCoIP)
all other traffic
NETWORK TRAFFIC LEGEND
AWS-managed
Auth: Directory Service
Session: WorkSpaces
Stream: WorkSpaces
Customer-managed
firewall needs to allow
for egress traffic
(Appendix A)
firewall needs to allow
for ingress traffic
(Appendix B)
WorkSpaces
auth (LDAP/RADIUS)
MFA (RADIUS)
(Optional)
auth-only
Questions?
aws.amazon.com/de/activate
Everything and Anything Startups
Need to Get Started on AWS

More Related Content

Viewers also liked

SonarQube e il debito tecnico - Matteo Emili
SonarQube e il debito tecnico - Matteo EmiliSonarQube e il debito tecnico - Matteo Emili
SonarQube e il debito tecnico - Matteo EmiliAntonio Liccardi
 
(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014
(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014
(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014Amazon Web Services
 
Powering Remote Developers with Amazon Workspaces
Powering Remote Developers with Amazon WorkspacesPowering Remote Developers with Amazon Workspaces
Powering Remote Developers with Amazon WorkspacesAmazon Web Services
 
Amazon WorkSpaces - Aadvanced Topics & Application Delivery
Amazon WorkSpaces - Aadvanced Topics & Application DeliveryAmazon WorkSpaces - Aadvanced Topics & Application Delivery
Amazon WorkSpaces - Aadvanced Topics & Application DeliveryAmazon Web Services
 
(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency
(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency
(ARC302) Running Lean Architectures: Optimizing for Cost EfficiencyAmazon Web Services
 
AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...
AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...
AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...Amazon Web Services
 
AWS Webcast - Getting Started with Amazon WorkSpaces
AWS Webcast - Getting Started with Amazon WorkSpacesAWS Webcast - Getting Started with Amazon WorkSpaces
AWS Webcast - Getting Started with Amazon WorkSpacesAmazon Web Services
 
Spock: A Highly Logical Way To Test
Spock: A Highly Logical Way To TestSpock: A Highly Logical Way To Test
Spock: A Highly Logical Way To TestHoward Lewis Ship
 
Moving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpacesMoving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpacesAmazon Web Services
 
Amazon AWS Workspace Howto
Amazon AWS Workspace HowtoAmazon AWS Workspace Howto
Amazon AWS Workspace Howtomailbhargav
 
Architecture Driven IT Modernization & Migration roadmap
Architecture Driven IT Modernization & Migration roadmapArchitecture Driven IT Modernization & Migration roadmap
Architecture Driven IT Modernization & Migration roadmapiCMG International
 
AWS Lunch and Learn - Workspaces. May 27th 2014
AWS Lunch and Learn - Workspaces. May 27th 2014AWS Lunch and Learn - Workspaces. May 27th 2014
AWS Lunch and Learn - Workspaces. May 27th 2014Amazon Web Services
 

Viewers also liked (14)

SonarQube e il debito tecnico - Matteo Emili
SonarQube e il debito tecnico - Matteo EmiliSonarQube e il debito tecnico - Matteo Emili
SonarQube e il debito tecnico - Matteo Emili
 
(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014
(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014
(SDD420) Amazon WorkSpaces: Advanced Topics and Deep Dive | AWS re:Invent 2014
 
Powering Remote Developers with Amazon Workspaces
Powering Remote Developers with Amazon WorkspacesPowering Remote Developers with Amazon Workspaces
Powering Remote Developers with Amazon Workspaces
 
Amazon WorkSpaces - Aadvanced Topics & Application Delivery
Amazon WorkSpaces - Aadvanced Topics & Application DeliveryAmazon WorkSpaces - Aadvanced Topics & Application Delivery
Amazon WorkSpaces - Aadvanced Topics & Application Delivery
 
(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency
(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency
(ARC302) Running Lean Architectures: Optimizing for Cost Efficiency
 
AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...
AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...
AWS April Webinar Series - Deploying and Managing Applications in Amazon Work...
 
AWS Webcast - Getting Started with Amazon WorkSpaces
AWS Webcast - Getting Started with Amazon WorkSpacesAWS Webcast - Getting Started with Amazon WorkSpaces
AWS Webcast - Getting Started with Amazon WorkSpaces
 
Spock: A Highly Logical Way To Test
Spock: A Highly Logical Way To TestSpock: A Highly Logical Way To Test
Spock: A Highly Logical Way To Test
 
Moving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpacesMoving your Desktops to the Cloud with Amazon WorkSpaces
Moving your Desktops to the Cloud with Amazon WorkSpaces
 
What are shooting stars? Could a metor be what you are wishing on? meteors, m...
What are shooting stars? Could a metor be what you are wishing on? meteors, m...What are shooting stars? Could a metor be what you are wishing on? meteors, m...
What are shooting stars? Could a metor be what you are wishing on? meteors, m...
 
Amazon AWS Workspace Howto
Amazon AWS Workspace HowtoAmazon AWS Workspace Howto
Amazon AWS Workspace Howto
 
Sistema Monetario Internacional
Sistema Monetario InternacionalSistema Monetario Internacional
Sistema Monetario Internacional
 
Architecture Driven IT Modernization & Migration roadmap
Architecture Driven IT Modernization & Migration roadmapArchitecture Driven IT Modernization & Migration roadmap
Architecture Driven IT Modernization & Migration roadmap
 
AWS Lunch and Learn - Workspaces. May 27th 2014
AWS Lunch and Learn - Workspaces. May 27th 2014AWS Lunch and Learn - Workspaces. May 27th 2014
AWS Lunch and Learn - Workspaces. May 27th 2014
 

More from AWS Germany

Analytics Web Day | From Theory to Practice: Big Data Stories from the Field
Analytics Web Day | From Theory to Practice: Big Data Stories from the FieldAnalytics Web Day | From Theory to Practice: Big Data Stories from the Field
Analytics Web Day | From Theory to Practice: Big Data Stories from the FieldAWS Germany
 
Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...
Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...
Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...AWS Germany
 
Modern Applications Web Day | Impress Your Friends with Your First Serverless...
Modern Applications Web Day | Impress Your Friends with Your First Serverless...Modern Applications Web Day | Impress Your Friends with Your First Serverless...
Modern Applications Web Day | Impress Your Friends with Your First Serverless...AWS Germany
 
Modern Applications Web Day | Manage Your Infrastructure and Configuration on...
Modern Applications Web Day | Manage Your Infrastructure and Configuration on...Modern Applications Web Day | Manage Your Infrastructure and Configuration on...
Modern Applications Web Day | Manage Your Infrastructure and Configuration on...AWS Germany
 
Modern Applications Web Day | Container Workloads on AWS
Modern Applications Web Day | Container Workloads on AWSModern Applications Web Day | Container Workloads on AWS
Modern Applications Web Day | Container Workloads on AWSAWS Germany
 
Modern Applications Web Day | Continuous Delivery to Amazon EKS with Spinnaker
Modern Applications Web Day | Continuous Delivery to Amazon EKS with SpinnakerModern Applications Web Day | Continuous Delivery to Amazon EKS with Spinnaker
Modern Applications Web Day | Continuous Delivery to Amazon EKS with SpinnakerAWS Germany
 
Building Smart Home skills for Alexa
Building Smart Home skills for AlexaBuilding Smart Home skills for Alexa
Building Smart Home skills for AlexaAWS Germany
 
Hotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructure
Hotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructureHotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructure
Hotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructureAWS Germany
 
Wild Rydes with Big Data/Kinesis focus: AWS Serverless Workshop
Wild Rydes with Big Data/Kinesis focus: AWS Serverless WorkshopWild Rydes with Big Data/Kinesis focus: AWS Serverless Workshop
Wild Rydes with Big Data/Kinesis focus: AWS Serverless WorkshopAWS Germany
 
Log Analytics with AWS
Log Analytics with AWSLog Analytics with AWS
Log Analytics with AWSAWS Germany
 
Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS
Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS
Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS AWS Germany
 
AWS Programme für Nonprofits
AWS Programme für NonprofitsAWS Programme für Nonprofits
AWS Programme für NonprofitsAWS Germany
 
Microservices and Data Design
Microservices and Data DesignMicroservices and Data Design
Microservices and Data DesignAWS Germany
 
Serverless vs. Developers – the real crash
Serverless vs. Developers – the real crashServerless vs. Developers – the real crash
Serverless vs. Developers – the real crashAWS Germany
 
Query your data in S3 with SQL and optimize for cost and performance
Query your data in S3 with SQL and optimize for cost and performanceQuery your data in S3 with SQL and optimize for cost and performance
Query your data in S3 with SQL and optimize for cost and performanceAWS Germany
 
Secret Management with Hashicorp’s Vault
Secret Management with Hashicorp’s VaultSecret Management with Hashicorp’s Vault
Secret Management with Hashicorp’s VaultAWS Germany
 
Scale to Infinity with ECS
Scale to Infinity with ECSScale to Infinity with ECS
Scale to Infinity with ECSAWS Germany
 
Containers on AWS - State of the Union
Containers on AWS - State of the UnionContainers on AWS - State of the Union
Containers on AWS - State of the UnionAWS Germany
 
Deploying and Scaling Your First Cloud Application with Amazon Lightsail
Deploying and Scaling Your First Cloud Application with Amazon LightsailDeploying and Scaling Your First Cloud Application with Amazon Lightsail
Deploying and Scaling Your First Cloud Application with Amazon LightsailAWS Germany
 

More from AWS Germany (20)

Analytics Web Day | From Theory to Practice: Big Data Stories from the Field
Analytics Web Day | From Theory to Practice: Big Data Stories from the FieldAnalytics Web Day | From Theory to Practice: Big Data Stories from the Field
Analytics Web Day | From Theory to Practice: Big Data Stories from the Field
 
Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...
Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...
Analytics Web Day | Query your Data in S3 with SQL and optimize for Cost and ...
 
Modern Applications Web Day | Impress Your Friends with Your First Serverless...
Modern Applications Web Day | Impress Your Friends with Your First Serverless...Modern Applications Web Day | Impress Your Friends with Your First Serverless...
Modern Applications Web Day | Impress Your Friends with Your First Serverless...
 
Modern Applications Web Day | Manage Your Infrastructure and Configuration on...
Modern Applications Web Day | Manage Your Infrastructure and Configuration on...Modern Applications Web Day | Manage Your Infrastructure and Configuration on...
Modern Applications Web Day | Manage Your Infrastructure and Configuration on...
 
Modern Applications Web Day | Container Workloads on AWS
Modern Applications Web Day | Container Workloads on AWSModern Applications Web Day | Container Workloads on AWS
Modern Applications Web Day | Container Workloads on AWS
 
Modern Applications Web Day | Continuous Delivery to Amazon EKS with Spinnaker
Modern Applications Web Day | Continuous Delivery to Amazon EKS with SpinnakerModern Applications Web Day | Continuous Delivery to Amazon EKS with Spinnaker
Modern Applications Web Day | Continuous Delivery to Amazon EKS with Spinnaker
 
Building Smart Home skills for Alexa
Building Smart Home skills for AlexaBuilding Smart Home skills for Alexa
Building Smart Home skills for Alexa
 
Hotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructure
Hotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructureHotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructure
Hotel or Taxi? "Sorting hat" for travel expenses with AWS ML infrastructure
 
Wild Rydes with Big Data/Kinesis focus: AWS Serverless Workshop
Wild Rydes with Big Data/Kinesis focus: AWS Serverless WorkshopWild Rydes with Big Data/Kinesis focus: AWS Serverless Workshop
Wild Rydes with Big Data/Kinesis focus: AWS Serverless Workshop
 
Log Analytics with AWS
Log Analytics with AWSLog Analytics with AWS
Log Analytics with AWS
 
Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS
Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS
Deep Dive into Concepts and Tools for Analyzing Streaming Data on AWS
 
AWS Programme für Nonprofits
AWS Programme für NonprofitsAWS Programme für Nonprofits
AWS Programme für Nonprofits
 
Microservices and Data Design
Microservices and Data DesignMicroservices and Data Design
Microservices and Data Design
 
Serverless vs. Developers – the real crash
Serverless vs. Developers – the real crashServerless vs. Developers – the real crash
Serverless vs. Developers – the real crash
 
Query your data in S3 with SQL and optimize for cost and performance
Query your data in S3 with SQL and optimize for cost and performanceQuery your data in S3 with SQL and optimize for cost and performance
Query your data in S3 with SQL and optimize for cost and performance
 
Secret Management with Hashicorp’s Vault
Secret Management with Hashicorp’s VaultSecret Management with Hashicorp’s Vault
Secret Management with Hashicorp’s Vault
 
EKS Workshop
 EKS Workshop EKS Workshop
EKS Workshop
 
Scale to Infinity with ECS
Scale to Infinity with ECSScale to Infinity with ECS
Scale to Infinity with ECS
 
Containers on AWS - State of the Union
Containers on AWS - State of the UnionContainers on AWS - State of the Union
Containers on AWS - State of the Union
 
Deploying and Scaling Your First Cloud Application with Amazon Lightsail
Deploying and Scaling Your First Cloud Application with Amazon LightsailDeploying and Scaling Your First Cloud Application with Amazon Lightsail
Deploying and Scaling Your First Cloud Application with Amazon Lightsail
 

Recently uploaded

Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 

Recently uploaded (20)

Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 

Amazon WorkSpaces: Advanced Topics and Deep Dive

  • 1. Amazon WorkSpaces: Advanced Topics and Deep Dive Justin Bradley, AWS Solutions Architect
  • 2. Agenda 1. Amazon WorkSpaces Overview 2. Amazon WorkSpaces Bundles 3. Amazon WorkSpaces Application Manager & Marketplace for Desktop Apps 4. Amazon Directory Service- Active Directory Integration 5. Network Considerations (Amazon Virtual Private Cloud) 6. Amazon WorkSpaces Communiction Flows
  • 3. The Work* Services WorkDocs Secure enterprise document collaboration WorkSpaces Virtual desktops Secure access from anywhere Monthly pricing Central sync, document feedback Secure access from anywhere S3 WorkSpaces Application Manager (WAM) Virtual applications Centralized application deployment Monthly subscription options WorkMail Secure email and calendaring Strong security controls Existing desktop, mobile support Directory Service Simple AD, AD Connector
  • 4. WorkSpaces: Fully Managed • Launch the number of WorkSpaces needed • All heavy lifting taken care of by AWS • Users receive email to install clients and connect WorkSpaces
  • 5. Amazon WorkSpaces Devices • iPad • Kindle Fire HDX (Keyboard & Mouse) • Android Tablet • Microsoft Windows • Mac • Zero clients • Cromebook
  • 6. Keep Data Secure and Available • No data stored on end-user device • Only Pixels delivered to users (PCoIP) • User volume backed by Amazon S3 • Multi-factor authentication (MFA) • Encrypted Storage Volumes Using KMS
  • 7. Keep Data Secure and Available • Securely backup and sync users data • Install on the WorkSpace and a PC or Mac • Data is backed up to Amazon S3 • Users can access their data when they need it WorkDocs Sync Client
  • 8. WorkSpaces: Bundles • WorkSpaces are provisioned from bundles • 3 WorkSpaces hardware configurations • 3 WorkSpaces images – Default, Office 2010 or Office 2013 Instance Type Image (AMI) Bundle Value (t2.small) Standard (t2.medium) Performance (m3.large) Default Custom No Office Office 2010 Professional (Plus) Office 2013 Professional (Plus)
  • 9. WorkSpaces: Choose Software and Hardware WorkSpaces Bundle Hardware Resources Applications Value 1 vCPU, 2 GiB Memory (t2.small), 10 GB User Storage Utilities (Adobe Reader, Internet Explorer 9, Firefox, 7-Zip, Adobe Flash) Value Plus 1 vCPU, 2 GiB Memory (t2.small), 10 GB User Storage Microsoft Office Professional 2010, Trend Micro Worry-Free Business Security, Utilities (Adobe Reader, Internet Explorer 9, Firefox, 7- Zip, Adobe Flash) Standard 2 vCPU, 4 GiB Memory (t2.medium), 50 GB User Storage Utilities (Adobe Reader, Internet Explorer 9, Firefox, 7-Zip, Adobe Flash) Standard Plus 2 vCPU, 4 GiB Memory (t2.medium), 50 GB User Storage Microsoft Office Professional 2010, Trend Micro Worry-Free Business Security, Utilities (Adobe Reader, Internet Explorer 9, Firefox, 7- Zip, Adobe Flash) Performance 2 vCPU, 7.5 GiB Memory (m3.large), 100 GB User Storage Utilities (Adobe Reader, Internet Explorer 9, Firefox, 7-Zip, Adobe Flash) Performance Plus 2 vCPU, 7.5 GiB Memory (m3.large), 100 GB User Storage Microsoft Office Professional 2010, Trend Micro Worry-Free Business Security, Utilities (Adobe Reader, Internet Explorer 9, Firefox, 7- Zip, Adobe Flash)
  • 10. WorkSpaces: Install your own software • No technical restrictions on software installation • Manage WorkSpaces like any other desktop • Use the tools you already use to distribute • WorkSpaces Application Manager (WAM) • WorkSpaces Marketplace for Desktop Apps • Create your own bundles (Custom)
  • 11. WAM: Managing Applications for your Users Amazon WorkSpaces Application Manager (Amazon WAM) Deploy and Manage Applications Package your own applications Upload applications where you own the license Subscribe from the AWS Marketplace for Desktop Apps
  • 12. Amazon WAM Benefits WorkSpaces Amazon WAM Catalog Deploy Apps for Desktop Apps Applications where you already own the license Line of business applications Curate a wide range of applications
  • 14. DEMO: WAM & Marketplace for Desktop Apps
  • 15. WorkSpaces: AD Integration • Users: Get to use existing Enterprise Credentials • IT: WorkSpaces control like regular desktops – Store in the OU that makes sense to you
  • 16. Simple AD Alex Hardy (ahardy) Emily McLane (emclane) Tim Nuberg (tnuberg) Simple AD AD Connector Alex Hardy (ahardy) Emily McLane (emclane) Tim Nuberg (tnuberg) AD AD Connector • 1 user = 1 directory username = 1 WorkSpaces desktop – Example: Alex Hardy -> ahardy -> desktop (ahardy) (Directory Instance 1) – Users cannot have 2 or more desktops per username, per directory instance WorkSpaces backed by..
  • 17. • Ensure existing AD is reachable (via VPC) • Create AD Connector + Directory Account • Launch WorkSpaces users in connected domain • This could be on-premises or in EC2 WorkSpaces: Corporate Directory Integration Steps Customer Corp Network 10.31.0.0/16 VPC 172.16.0.0/16 AD Connector ENI ENI VPN Connection Active Directory WorkSpaces (Eth1)
  • 18. Availability Zone B Private subnet DC4 Corporate Network London DC1 VPN / Direct Connect Paris DC2 Cost 50 Availability Zone A Private subnet DC3 Cost 10 company.local company.local One single identity, data center extension mode (Rely on Active Directory Sites, Read-Only or not) WorkSpaces: Extend customer domain
  • 19. WorkSpaces: Network Considerations (VPC) • directory : a Directory Service instance • 1 directory spans exactly two subnets • 1 directory = 2 EC2 instances (1 per subnet) • You can have multiple directories in 1 VPC • Each directory has its own registration code • Zero clients: each regcode needs its own url Subnet A (AZ 1) Subnet B (AZ 2) regcode (example: WSpdx+A1B2C3) zero client url (example: https://url1.company.com) Visualization of a Directory Instance laptops, desktops, tablets zero clients
  • 20. WorkSpaces: Network Considerations (VPC) • VPC Subnet Size – AWS Fact: Largest VPC size: /16 (65K addresses) • WorkSpaces reside in subnets as defined for Directory Connector • Each Subnet – 6 IP’s • Regional proximity to users • Tie into global network via Direct Connect • Use Existing IP space • Restrict corporate network access when necessary
  • 21. Auth/Session Gateways Public AWS Endpoint WorkSpaces (network entry point) Customer VPC EC2 WorkSpaces: Communication Flow Active Directory corp servers Direct Connect or VPN Customer Corp Net Users Customer Internet AD Connector Public AWS Endpoint Streaming Gateway 7 1 2 3 45 6a 6b 8 9 WorkSpaces auth/session (SSL) WorkSpaces streaming (PCoIP) all other traffic NETWORK TRAFFIC LEGEND AWS-managed Auth: Directory Service Session: WorkSpaces Stream: WorkSpaces Customer-managed firewall needs to allow for egress traffic (Appendix A) firewall needs to allow for ingress traffic (Appendix B) WorkSpaces auth (LDAP/RADIUS) MFA (RADIUS) (Optional) auth-only
  • 23. aws.amazon.com/de/activate Everything and Anything Startups Need to Get Started on AWS