Maintained with ☕️ by
IcePanel logo

AWS Directory Service supports smart card authentication in AWS GovCloud (US-East) Region

Share

Services

Starting today, you can use Common Access Card (CAC) and Personal Identity Verification (PIV) smart cards to authenticate users into Amazon WorkSpaces through your self-managed Active Directory (AD) and AWS Directory Service AD Connector in the AWS GovCloud (US-East) Region. Additionally, you can now use the AWS Management Console to configure smart card authentication with AWS Directory Service. When enabled, users select their smart card at the WorkSpaces login screen and enter a PIN to authenticate, instead of using a username and password. From there, the Windows or Linux virtual desktop uses the smart card to authenticate with Active Directory from the native desktop operating system. Smart card support is available on WorkSpaces when using the [WorkSpaces Streaming Protocol](https://aws.amazon.com/workspaces/wsp/) (WSP). With AWS Directory Service and Amazon WorkSpaces with WSP, users can use smart cards to authenticate into a WorkSpaces instance (pre-session authentication) or into protected applications from within a WorkSpaces instance (in-session authentication). To get started, visit [Enable mTLS authentication in AD Connector for use with smart cards](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ad%5Fconnector%5Fclientauth.html) in the [AWS Directory Service Administration Guide](https://docs.aws.amazon.com/directoryservice/latest/admin-guide/what%5Fis.html). To learn about smart card support in Amazon WorkSpaces, visit [Use Smart Cards for Authentication](https://docs.aws.amazon.com/workspaces/latest/adminguide/smart-cards.html) in the [Amazon WorkSpaces Administration Guide](https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces.html).