
Advance your Amazon AppStream 2.0 skills with VPC readiness, CloudFormation deployments, and image pipelines for Windows and Linux, plus Active Directory joined fleets and SAML or IAM Identity Center integrations.
Create a VPC with two public and two private subnets across two availability zones, route private traffic via NAT gateways for internet access, following the Well-Architected framework and CloudFormation.
Learn to deploy an AWS managed Microsoft Active Directory for AppStream 2.0, configure subnets in two availability zones, join fleets to the domain, and manage AD from an EC2 instance.
Create a DHCP options set in a vpc to enable AppStream 2.0 instances to discover the Microsoft managed Active Directory via DNS and join the AD domain.
Provision an EC2 instance and enable automatic domain join to a managed Active Directory, using an IAM role for SSM and AD integration for seamless domain management.
Configure an AppStream 2.0 fleet to join your Active Directory by creating a directory config with the directory's FQ and OU. Modify networking and enable domain joining for SAML access.
Learn how to enable SAML authentication for domain-joined AppStream 2.0 using AWS Identity Center, publishing an AppStream application, linking IAM Identity Center roles, and testing sessions.
Configure IAM Identity Center in AWS, selecting internal directory and planning Active Directory as single future identity source, while setting up permission sets and user or group access to accounts.
Publish an app in IAM Identity Center by adding the pre-integrated App Stream, naming the stack, downloading the metadata file, and preparing relay state and access.
Create an identity provider from the IAM Identity Center metadata for this AppStream application, then create a SAML 2 role, update trust relationships, and attach inline policy to enable streaming.
Reconfigure the application in AWS Identity Center by editing the relay state for the Sydney region, and updating the stack name, account ID, and attribute mappings to include the role.
Create a user in IAM Identity Center, assign them to the two stack one app, sign in, and start the fleet, noting domain joined versus generic non-domain logins.
Learn to log in to an AppStream 2.0 fleet as a domain user with IAM Identity Center, matching Active Directory credentials and a one-time password.
Switch IAM Identity Center to use Active Directory as the identity source, enable AWS managed Microsoft AD, and synchronize users and groups to assign AppStream access by group.
Automate AppStream infrastructure with CloudFormation template to deploy stacks, fleets, and resources. Learn template anatomy, parameters, conditions, and how to configure subnets, security groups, image names, and scaling.
Automate the creation of AppStream Windows images with a fully scripted pipeline using CloudFormation, Lambda, Step Functions, and S3, including Notepad++, Putty, and Draw.io.
Configure an automated Linux image pipeline for Amazon AppStream 2.0 using CloudFormation, Lambda, S3, and image builder, enabling remote SSH access and installing Putty and LibreOffice.
Explore AppStream settings persistence for Windows instances, saving user profiles to a VHD on S3, encrypted in transit and at rest, and affecting logon performance.
Implement SAML and certificate-based authentication for Amazon Workspaces and AppStream, enabling passwordless access with IDPs, while following labs and prerequisites to configure, test, and validate across platforms.
Configure a VPC for workspaces and AppStream, creating public and private subnets across availability zones, with a NAT gateway, DNS host names, and VPC endpoints.
Deploy a Windows 2022 EC2 instance, install Active Directory and Certificate Services, configure networking, IAM roles, and secure access via Session Manager or Fleet Manager to create a domain controller.
Install and configure active directory domain services on an EC2 instance, promote it to a domain controller for Miyuki demo cloud, and implement certificate services with an enterprise root CA.
Design Active Directory DNS in AWS by choosing Route 53 forwarding or defaulting DNS to the AD, enabling resolution of AWS endpoints and AD across the VPC.
Create an active directory connector to allow workspaces to communicate with an ec2 active directory, configure vpc subnets and dns, register connector, and deploy workspaces using the ad connector.
Provision an Amazon WorkSpaces workspace with Windows Server 2022, 2 vcpu, 4 gb ram, auto stop after 1 hour, tied to an Active Directory domain for SAML and certificate-based authentication.
Learn how to test connectivity to Amazon WorkSpaces with a standard login, obtain a registration code, download the client, and sign in as an Active Directory domain user.
Configure saml for workspaces using Okta as the idp; create a saml identity provider in aws iam, define a role and policy, and complete assertions and relay state.
Set up an IAM identity provider in AWS for Okta and create a federation role with an inline policy, enabling users from Okta to stream workspaces in AWS AppStream 2.0.
Complete the Okta saml configuration by editing the app, setting relay state, adding attribute statements for email, role session name, and arn, assign to users, and test.
Enable SAML 2.0 authentication for AWS Workspaces by configuring the directory, linking the Okta app via sign-on URL, and enforcing SAML with a test login in Okta.
Explore configuring Saml single sign-on for Amazon WorkSpaces via Okta, linking Active Directory users, launching the WorkSpaces app, and preparing certificate-based authentication.
Publish an S3 bucket via CloudFront with a bucket policy, then configure a subordinate CA with short‑lived certificates for AD certificate services to enable authentication on workspaces and AppStream.
Configure saml 2.0 with certificate based authentication in Okta by adding required attributes, mapping the my AUC demo cloud profile, and updating saml settings for the workspaces app.
Configure initial certificate-based authentication by securing a CRL S3 bucket with CloudFront access control and provisioning a private certificate authority with a subordinate template in AD and AWS CLI.
Convert downloaded certificates to a subordinate pem file, import into a subordinate certificate authority, publish the certificate to Active Directory, and enable certificate-based authentication in the workspaces directory.
Launch the workspaces app and confirm that Saml authentication and certificate-based authentication are both enabled. Use the default browser to sign in with Okta, then auto sign in without passwords.
Configure SAML and certificate-based authentication for Amazon AppStream 2.0 by integrating Okta as the identity provider, creating a trusted IAM role, and publishing AppStream apps.
Enable certificate based authentication in the AppStream directory config and demonstrate domain user sign-ins via Okta, delivering seamless, prompt-free access to AppStream and workspaces.
Wrap up the Amazon AppStream 2.0 advanced series by reviewing VPC readiness, CloudFormation deployments, DHCP options, Active Directory integration, and automatic image pipelines.
Welcome to the Advanced Amazon AppStream 2.0 (AS2) course by Masters Of Cloud!
This course has been designed as a follow on 'deep dive' course to the 'Amazon AppStream - Introduction' (also by Masters of Cloud and also on Udemy!)
What is Amazon AppStream we hear you ask? Well take a look at our other free 'Amazon AppStream 2.0 - Introduction' udemy course first!
This advanced course builds on your knowledge from the introductory course by expanding your knowledge of the following advanced configurations for Amazon AppStream 2.0.
AppStream Settings Persistence
VPC Readiness, DHCP Options Sets and CloudFormation deployments
AppStream Infrastructure Deployment via CloudFormation
Configuring SAML and Certificate Based Authentication (CBA) for Amazon AppStream 2.0
AppStream SAML Integration and Active Directory Joined AppStream Fleets and Managed AD
IAM Identity Center Integration and M-AD Synchronisation
Creating an Automatic AppStream Image Pipeline - Windows and Linux
We also have provided CloudFormation templates to assist you with deploying the Course infrastructure to get you up and running in no time and to complement the course with even more cloudy skills for technologies like CloudFormation, VPC Creation, Managed Microsoft Active Directory.
Prior Learning: You should have basic prior knowledge of fundamental networking (DNS, Subnetting, Routing, DHCP) and cloud concepts (AWS VPC) and be competent with Microsoft Windows operating systems and Linux Operating Systems.
Any questions, queries, feedback or problems please don't hesitate to get in touch via the Udemy website!
Thank you for learning the future with Masters Of Cloud!