View a markdown version of this page

Secure Remote Worker Environment - Secure Remote Worker Environment

Secure Remote Worker Environment

Publication date: January 31, 2022 (Diagram history)

This architecture shows how to build a secure desktop environment for remote workers. Workers can access key line-of-business applications and data.

Secure Remote Worker Environment

Architecture diagram showing a secure remote worker environment with Amazon WorkSpaces.
  1. Users connect to their desktop by using the Amazon WorkSpaces application with a username, password, and MFA code.

  2. The Amazon WorkSpaces authentication gateway authenticates against Amazon DynamoDB Streams.

  3. The MFA code authenticates against the MFA service's RADIUS server (for example, OneLogin).

  4. Users connect to their desktop through Amazon WorkSpaces.

  5. Users access core systems and files hosted on Amazon Elastic Compute Cloud and Amazon FSx.

  6. Group policy in Active Directory prevents unwanted activities, such as printing to local printers from Amazon WorkSpaces.

  7. Domain Controller DNS forwards to RouteĀ 53 VPC DNS resolver with applied RouteĀ 53 Resolver DNS Firewall rules.

  8. AWS Network Firewall filters outbound internet traffic, then routes it through a NAT gateway and internet gateway to the public internet.

  9. Firewall rules block outbound traffic to unwanted sites (such as file-sharing platforms) to prevent data leaks.

Further reading

For additional information, refer to

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

January 31, 2022

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.