Home icon

Simplifying Active Directory domain join with AWS Systems Manager

Microsoft Workloads on AWS Blog



This article describes a solution for managing Microsoft Active Directory domain membership for Amazon EC2 Windows instances using AWS Systems Manager Automation. It demonstrates how to use Automation runbooks to dynamically automate domain join and unjoin activities with Active Directory, eliminating the need for legacy scripts or third-party software.

Specifically, the article covers:

  • Solution overview and workflow of the Automation runbook
  • Key parameters and steps involved in the runbook for domain join and unjoin
  • Using AWS Secrets Manager to securely store and retrieve Active Directory credentials
  • Configuring required IAM permissions for the EC2 instances
  • Step-by-step walkthrough of manually executing the runbook to join/unjoin an EC2 instance
  • Troubleshooting failed executions using the console outputs
  • Cleanup of resources created by the example CloudFormation template


Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Aug 31
2026
AWS Elastic Beanstalk now supports Active Directory domain join for Windows Server environments
Jul 29
2024
Active Directory Domain Services integration with Amazon Route 53
Aug 12
2024
Simplify Active Directory authentication with a custom identity provider for AWS Transfer Family
Nov 22
2024
Event-driven Active Directory domain join with Amazon EventBridge

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.