This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::WorkSpaces::Directory
The AWS::WorkSpaces::Directory resource Property description not available. for WorkSpaces.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::WorkSpaces::Directory", "Properties" : { "ActiveDirectoryConfig" :ActiveDirectoryConfig, "CertificateBasedAuthProperties" :CertificateBasedAuthProperties, "EnableSelfService" :Boolean, "EndpointEncryptionMode" :String, "IdcInstanceArn" :String, "IpGroupIds" :[ String, ... ], "MicrosoftEntraConfig" :MicrosoftEntraConfig, "SamlProperties" :SamlProperties, "SelfservicePermissions" :SelfservicePermissions, "StreamingProperties" :StreamingProperties, "SubnetIds" :[ String, ... ], "Tags" :[ Tag, ... ], "Tenancy" :String, "UserIdentityType" :String, "WorkspaceAccessProperties" :WorkspaceAccessProperties, "WorkspaceCreationProperties" :DefaultWorkspaceCreationProperties, "WorkspaceDirectoryDescription" :String, "WorkspaceDirectoryName" :String, "WorkspaceType" :String} }
YAML
Type: AWS::WorkSpaces::Directory Properties: ActiveDirectoryConfig:ActiveDirectoryConfigCertificateBasedAuthProperties:CertificateBasedAuthPropertiesEnableSelfService:BooleanEndpointEncryptionMode:StringIdcInstanceArn:StringIpGroupIds:- StringMicrosoftEntraConfig:MicrosoftEntraConfigSamlProperties:SamlPropertiesSelfservicePermissions:SelfservicePermissionsStreamingProperties:StreamingPropertiesSubnetIds:- StringTags:- TagTenancy:StringUserIdentityType:StringWorkspaceAccessProperties:WorkspaceAccessPropertiesWorkspaceCreationProperties:DefaultWorkspaceCreationPropertiesWorkspaceDirectoryDescription:StringWorkspaceDirectoryName:StringWorkspaceType:String
Properties
ActiveDirectoryConfig-
Information about the Active Directory config.
Required: No
Type: ActiveDirectoryConfig
Update requires: Replacement
CertificateBasedAuthProperties-
The certificate-based authentication properties used to authenticate SAML 2.0 Identity Provider (IdP) user identities to Active Directory for WorkSpaces login.
Required: No
Type: CertificateBasedAuthProperties
Update requires: No interruption
EnableSelfServiceProperty description not available.
Required: No
Type: Boolean
Update requires: Replacement
EndpointEncryptionMode-
Endpoint encryption mode that allows you to configure the specified directory between Standard TLS and FIPS 140-2 validated mode.
Required: No
Type: String
Allowed values:
STANDARD_TLS | FIPS_VALIDATEDUpdate requires: No interruption
IdcInstanceArnProperty description not available.
Required: No
Type: String
Pattern:
^arn:aws[a-z-]{0,7}:[A-Za-z0-9][A-za-z0-9_/.-]{0,62}:[A-za-z0-9_/.-]{0,63}:[A-za-z0-9_/.-]{0,63}:[A-Za-z0-9][A-Za-z0-9:_/+=,@.\\-]{0,1023}$Update requires: Replacement
IpGroupIds-
The identifiers of the IP access control groups associated with the directory.
Required: No
Type: Array of String
Update requires: No interruption
MicrosoftEntraConfig-
Specifies details about Microsoft Entra configurations.
Required: No
Type: MicrosoftEntraConfig
Update requires: Replacement
SamlProperties-
Describes the enablement status, user access URL, and relay state parameter name that are used for configuring federation with an SAML 2.0 identity provider.
Required: No
Type: SamlProperties
Update requires: No interruption
SelfservicePermissions-
The default self-service permissions for WorkSpaces in the directory.
Required: No
Type: SelfservicePermissions
Update requires: No interruption
StreamingProperties-
The streaming properties to configure.
Required: No
Type: StreamingProperties
Update requires: No interruption
SubnetIds-
The identifiers of the subnets used with the directory.
Required: No
Type: Array of String
Minimum:
15 | 0Maximum:
24 | 2Update requires: Replacement
Property description not available.
Required: No
Type: Array of Tag
Update requires: No interruption
Tenancy-
Specifies whether the directory is dedicated or shared. To use Bring Your Own License (BYOL), this value must be set to
DEDICATED. For more information, see Bring Your Own Windows Desktop Images.Required: No
Type: String
Allowed values:
DEDICATED | SHAREDUpdate requires: Replacement
UserIdentityType-
Indicates the identity type of the specifired user.
Required: No
Type: String
Allowed values:
CUSTOMER_MANAGED | AWS_DIRECTORY_SERVICE | AWS_IAM_IDENTITY_CENTERUpdate requires: Replacement
WorkspaceAccessProperties-
The devices and operating systems that users can use to access WorkSpaces.
Required: No
Type: WorkspaceAccessProperties
Update requires: No interruption
WorkspaceCreationProperties-
The default creation properties for all WorkSpaces in the directory.
Required: No
Type: DefaultWorkspaceCreationProperties
Update requires: No interruption
WorkspaceDirectoryDescription-
The description of the WorkSpace directory
Required: No
Type: String
Pattern:
^([a-zA-Z0-9_])[\\a-zA-Z0-9_@#%*+=:?./!\s-]{1,255}$Update requires: Replacement
WorkspaceDirectoryName-
The name fo the WorkSpace directory.
Required: No
Type: String
Pattern:
^[a-zA-Z0-9][a-zA-Z0-9_.\s-]{1,64}$Update requires: Replacement
WorkspaceType-
Indicates whether the directory's WorkSpace type is personal or pools.
Required: No
Type: String
Allowed values:
PERSONAL | POOLSUpdate requires: Replacement
Return values
Ref
Fn::GetAtt
Alias-
The directory alias.
ArnProperty description not available.
CustomerUserName-
The user name for the service account.
DirectoryId-
The directory identifier.
DirectoryName-
The name of the directory.
DirectoryType-
The directory type.
DnsIpAddresses-
The IP addresses of the DNS servers for the directory.
DnsIpv6Addresses-
The IPv6 addresses of the DNS servers for the directory.
IamRoleId-
The identifier of the IAM role. This is the role that allows Amazon WorkSpaces to make calls to other services, such as Amazon EC2, on your behalf.
RegistrationCode-
The registration code for the directory. This is the code that users enter in their Amazon WorkSpaces client application to connect to the directory.
State-
The state of the directory's registration with Amazon WorkSpaces. After a directory is deregistered, the
DEREGISTEREDstate is returned very briefly before the directory metadata is cleaned up, so this state is rarely returned. To confirm that a directory is deregistered, check for the directory ID by using DescribeWorkspaceDirectories. If the directory ID isn't returned, then the directory has been successfully deregistered. WorkspaceSecurityGroupId-
The identifier of the security group that is assigned to new WorkSpaces.