getting started with amazon enterprise applications | aws public sector summit 2016

23
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Nathan McGuirt, AWS Senior Solutions Architect June 20, 2016 Getting Started with AWS Enterprise Applications Amazon WorkSpaces, Amazon WorkMail, Amazon WorkDocs, and AWS Directory Service

Upload: amazon-web-services

Post on 14-Apr-2017

262 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Nathan McGuirt, AWS Senior Solutions Architect

June 20, 2016

Getting Started with AWS Enterprise Applications

Amazon WorkSpaces, Amazon WorkMail, Amazon WorkDocs, and AWS Directory Service

Page 2: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Expectations

• Introduce the services and their features• Discuss prerequisites and potential architectures• Discuss high-level deployment steps

Page 3: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

AWS Directory Service

Managed High-Availability AD in AWS

Page 4: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Directory Service – three flavors

• Microsoft AD• Simple AD• AD Connector

Page 5: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Prerequisites and requirements

• VPC with 2 subnets in different AZs• VPC must be default tenancy• For Simple AD and Microsoft AD

• Subnet ACLs that allow replication• For AD Connector

• Network path to an AD domain• Privileged user account in domain

Page 6: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Example architectures – Simple AD & Microsoft AD

DMZ A

APP BDMZ B

APP B DATA A

DATA B

Customer Operated VPC

AWS Operated Account(s)

DC

DC

Page 7: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Example architectures – AD Connector

DMZ A

APP BDMZ B

APP A DATA A

DATA B

DC

DC

Customer Operated VPC

AWS Operated Account(s)

Corporate DC

Page 8: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Secure, Cost Effective, Managed Cloud Desktop

Amazon Workspaces

Page 9: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Amazon WorkSpaces use cases

Temporary workers

Dev/Test

Securing data BYOD

Training and labs Demos

Page 10: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

WorkSpaces features and benefits• Persistent desktop experience for users• Users authenticate against your directory• Data stored in AWS, not on devices• Support for inexpensive thin clients and tablets• API Support• Amazon CloudWatch metrics• Microsoft Windows 7 BYOL support• Tagging support

Page 11: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Prerequisites and requirements

• Directory Service directory registered with WorkSpaces

• Supported device with client installed• Client network with <250 ms latency to service

Page 12: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

eth0 serves WorkSpaces pixels back to the client

device

eth1 serves traffic to:• Internet • Resources in

VPC• Resources on-

premiseseth0 eth1

On Premises Network

Customer

eni

Internet Gateway

Internet

AWS Direct ConnectAmazon WorkSpaces are dual-homed Windows Server 2008 R2 instances

with Windows 7 experience

eth1 is in the customer VPC

Amazon WorkSpaces data flows

Amazon

Client connects to a “WorkSpaces gateway” between your device and your WorkSpaces

PCoIPTCP and UDP

4172

Internet

Page 13: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Deeper architecture view

DMZ A

APP BDMZ B

APP A DATA A

DATA B

Customer Operated VPC

AWS Operated Account(s)

Corporate DC

Internet

P

Page 14: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Secure, Managed Business Email

Amazon WorkMail

Page 15: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Features

• General availability • Built-in data-at-rest encryption with AWS KMS• Native Outlook support on Windows or Mac OS X• ActiveSync Mobile Client support• Mobile device policies for PIN and encryption

Page 16: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Requirements

• Active Directory• Simple AD, Microsoft AD, or AD Connector

• Supported client• Domain (optional)

Page 17: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Architecture

Page 18: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Secure, Managed Enterprise File Storage and Sharing

Amazon WorkDocs

Page 19: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Features

• Comment on files, send to others for feedback• Access and sync across multiple devices• Encrypted in transit and at rest• Mobile app for iOS, Android, Fire• Windows and Mac OS sync clients

Page 20: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Requirements

• Active Directory• Simple AD, Microsoft AD, or AD Connector

Page 21: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Architecture

Page 22: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Demo

Page 23: Getting Started with Amazon Enterprise Applications | AWS Public Sector Summit 2016

Thank you!