Understanding AWS Directory Service
Microsoft AD is a complex and feature-rich enterprise directory service. Beyond basic LDAP capabilities for user management and authentication, it can also be used for machine management, including device authentication and authorization, DNS, certificate authority services, endpoint policy management and enforcement, and federation services. Over the years, it has been positioned and marketed as a one-stop-shop for enterprise workloads. Unfortunately, the feature-richness that made AD an enterprise mainstay for over 20 years is also why it can become insecure or misconfigured. This is why AD implementations are at the heart of so many security incidents. Its monolithic nature, broad set of services, and wide network port utilization also make it a tempting target for bad actors and limit its capability to securely operate outside of an established network perimeter.
Though traditional on-premises AD may not be naturally suited for an internet...