Home icon

Hardening DNS Resolution for Amazon WorkSpaces Personal

Desktop & Application Streaming Blog



This article discusses how to harden DNS resolution for Amazon WorkSpaces Personal, a managed Desktop-as-a-Service (DaaS) solution. It explains that WorkSpaces have two network interfaces: one in the service-owned Management Network and one in the customer-owned VPC. Due to Windows' Smart Multi-Homed Name Resolution (SMHNR), DNS queries from WorkSpaces may be sent to resolvers in the Management Network, which could raise security concerns for customers.

Specifically, the article covers:

  • The architecture of WorkSpaces with two network interfaces
  • The role of SMHNR in causing DNS queries to the Management Network
  • Solution 1: Using Windows Defender Firewall to block DNS traffic to the Management Network
  • Solution 2: Deploying a Name Resolution Policy rule to route all DNS queries to the customer's network
  • Steps to configure both solutions using Group Policy Objects
  • Cleanup steps to remove the configured rules and GPOs


Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Apr 6
2026
Amazon WorkSpaces Personal now supports unique DNS names for PrivateLink
Aug 22
2024
Leverage a one-way trust with Amazon WorkSpaces for cross-domain usage
Aug 29
2024
Utilizing CloudWatch Internet Monitor with Amazon WorkSpaces Personal
Jul 24
2024
DNS best practices for Amazon Route 53

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.