Secure Remote Worker Environment
Publication date: January 31, 2022 (Diagram history)
This architecture shows how to build a secure desktop environment for remote workers. Workers can access key line-of-business applications and data.
Secure Remote Worker Environment
-
Users connect to their desktop by using the Amazon WorkSpaces application with a username, password, and MFA code.
-
The Amazon WorkSpaces authentication gateway authenticates against Amazon DynamoDB Streams.
-
The MFA code authenticates against the MFA service's RADIUS server (for example, OneLogin).
-
Users connect to their desktop through Amazon WorkSpaces.
-
Users access core systems and files hosted on Amazon Elastic Compute Cloud and Amazon FSx.
-
Group policy in Active Directory prevents unwanted activities, such as printing to local printers from Amazon WorkSpaces.
-
Domain Controller DNS forwards to RouteĀ 53 VPC DNS resolver with applied RouteĀ 53 Resolver DNS Firewall rules.
-
AWS Network Firewall filters outbound internet traffic, then routes it through a NAT gateway and internet gateway to the public internet.
-
Firewall rules block outbound traffic to unwanted sites (such as file-sharing platforms) to prevent data leaks.
Further reading
For additional information, refer to
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Initial publication | Reference architecture diagram first published. | January 31, 2022 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.