Managed Active Directory across clouds
A domain the cloud runs - AWS Managed Microsoft AD, Entra Domain Services, Managed Microsoft AD on Google Cloud - with the legacy protocols off and the networks that may reach it named.
3 verified modules - all static-validated and publish-checked; live-test pending.
Compare by provider
| Provider | Module | Verification |
|---|---|---|
| AWS | Managed Microsoft AD, Simple AD or AD Connector | static-validated |
| Azure | A Managed AD Domain with Legacy Protocols Off and Its Prerequisites Created | static-validated |
| Google Cloud | Managed Microsoft AD Reachable Only from Named VPCs, in More than One Region | static-validated |
How to choose
Compare what the domain is synchronised from (Entra ID, nothing, or a trust to your forest), which regions or zones hold controllers, whether LDAPS is offered and to whom, and how the admin credential is handled: set out of band, in state, or in a secret store the module reads.
When not to use
A managed domain is a domain: NTLM, Kerberos and LDAP behave as they did in 2003 unless the legacy options are turned off, and every machine joined to it trusts it completely. It is billed by the hour whether anything joins or not.