AWS Managed AD Domain Join
Join EC2 instances to an AWS Managed Microsoft AD directory using the built-in aws:domainJoin SSM action.
Prerequisites
- AWS Managed Microsoft AD directory already created
- EC2 instances running Windows Server with SSM agent
- Instance IAM role with
AmazonSSMManagedInstanceCorepolicy - Security groups allowing AD traffic between instances and AD (ports 389, 636, 88, 445, etc.)
Cross-VPC Security Group Configuration
AWS Managed AD automatically creates a security group whose default rules are scoped only to the VPC where the directory is deployed. If you have instances to domain-join in other VPCs (spoke accounts, peered VPCs, Transit Gateway-connected VPCs), you must add rules for those networks or the instances cannot communicate with the domain controllers even if network connectivity exists. Use the security_group_rules.allow_ad_ports_from option on the directory to grant a network the full AD port set in one entry — see Managed Active Directory.
Configuration
Step 1: Define the Domain Join Document
Step 2: Reference Managed AD Directory
The directory input must match a key in your managed_ads variable:
See Managed Active Directory for the full managed_ads schema and defaults.
Step 3: Associate with EC2 Instances
Reference the domain join document in your instance configuration:
How It Works
- Terraform creates an SSM document using the AWS-provided
aws:domainJoinaction - The document automatically retrieves directory details from the AWS Directory Service
- When the instance launches, SSM executes the domain join
- The instance joins the domain and reboots automatically
Behind the Scenes
The module translates your configuration into an SSM document that looks like:
{
"schemaVersion": "2.2",
"description": "aws:domainJoin",
"mainSteps": [{
"action": "aws:domainJoin",
"name": "domainJoin",
"inputs": {
"directoryId": "d-1234567890",
"directoryName": "epic.local",
"dnsIpAddresses": ["10.0.1.10", "10.0.1.11"]
}
}]
}
Advantages
- Simple Configuration - AWS handles most of the complexity
- No Credential Management - AWS manages domain credentials internally
- Automatic DNS - Directory Service provides DNS automatically
- Built-in Support - Uses AWS-native SSM action
Limitations
- Only works with AWS Managed Microsoft AD (not Simple AD or AD Connector)
- Cannot specify custom OU placement with managed AD
- Directory must be in the same AWS account and region
Troubleshooting
Instance Not Joining Domain
- Verify SSM agent is running: Check SSM Fleet Manager
- Check IAM permissions: Instance profile must have SSM policies
- Verify network connectivity: Security groups must allow AD ports
- Review SSM command history: Look for execution errors
Finding SSM Execution Logs
- Navigate to AWS Systems Manager → Run Command
- Find the command execution for your instance
- View output to see detailed error messages