Multi-Factor Authentication in Amazon WorkSpaces

(Update) On the topic of Multi-Factor Authentication, we recommend two new courses we’ve released Understanding of AWS Authentication, Authorization & Accounting and Implementing Multi-Factor Authentication on Azure. 


Just a few days ago we talked about how to protect your AWS based server with Multi-Factor Authentication.

This not-so-new technology is spreading more and more, especially given that it hugely increases security at the very tiny inconvenience of entering a One-Time-Password every time you log in to your system.  The OTP can be generated either by a physical or a virtual device, like for example a smartphone app. This is extremely convenient, especially considered that we always (or almost always) have our smartphone around, and even if someone stoles it, the thief still hasn’t all the pieces needed to log into our account. So, we all like MFA, and we like it so much that Amazon added support for Multi-Factor Authentication in Amazon WorkSpaces, one if the services of its AWS family. Even better: it’s available for free!
Amazon WorkSpaces Logo

What is Amazon WorkSpaces?

We don’t talk about WorkSpaces that often on this blog. Actually, it’s definitely not a first-tier service of AWS. Nevertheless, it’s having quite a success and has many interesting applications, so it’s still good to learn more about it.
Amazon describes WorkSpaces as a “fully managed desktop computing service in the cloud“. In other words, WorkSpaces allows you to launch cloud-based Windows desktop instances that users can access from their own device, including mobile devices like iPad, Android tablets, and of course Amazon’s Kindle Fire. End users will have a complete Windows 7 based desktop interface, easing all the burden of installing device drivers or setting up applications. As it happens with many SaaS solutions (or maybe we should call it an “Operating System as a Service”?), the price for this convenience is a loss of flexibility at a certain degree. Anyway, WorkSpaces still is a viable solution, with a high-security level granted by the adoption of the PCoIP protocol, and with lower costs than other on-premises Virtual Desktop Infrastructure.

How to enable MFA in Amazon WorkSpaces

Amazon added support for MFA using an on-premises RADIUS server, meaning that users will be able to authenticate themselves using the same mechanism that they already use for other remote access systems of their organization. So, after MFA has been enabled and configured, WorkSpaces users will just log in by entering their usual Active Directory user name and password, and then the One-Time Password supplied by either a hardware or a virtual device, just like the smartphone application we discussed earlier.

The new WorkSpaces feature works with any security provider supporting RADIUS. Amazon added support for many protocols, including PAP, CHAP, MS-CHAP1, and MS-CHAP2, which should be enough to grant compatibility with the vast majority of the existing infrastructures. To actually enable MFA, the WorkSpaces administrator must configure the new feature by entering the connection information for the on-premises RADIUS server in the Directories section of the WorkSpaces console. If high availability is a concern, it’s possible to provide multiple RADIUS servers, either adding all their IP addresses or deploying an Elastic Load Balancer in front of them.

Avatar

Written by

Andrea Colangelo

Software Engineer with a solid focus on QA and an extensive experience in ICT. Above all, Andrea has a very strong interest in Free and Open Source Software, and he is a Debian and Ubuntu Developer since years. Non-tech interests include: Rugby, Jazz music and Cooking.


Related Posts

Joe Nemer
Joe Nemer
— April 2, 2020

Breaking News: All AWS Certification Exams Now Available Online

Remote proctoring for all AWS certifications Cloud Academy is an Advanced AWS Technology Partner, and we were are happy to announce all AWS certification exams are available online!  What does this mean for you? You can stay focused on your certification goal. Or you can start a cert...

Read more
  • AWS
  • AWS certification
  • AWS Certifications
Connie Benton
Connie Benton
— April 1, 2020

How To Build a Career with AWS Certifications

From Iaas and PaaS solutions to digital marketing, cloud computing reshapes the world of technology. As the influence of this technology grows, so does investment. Tens of billions of dollars are being spent on cloud computing-related services each year. This influx is continuing to inc...

Read more
  • AWS
  • Certifications
Vijayakumar Athithan
Vijayakumar Athithan
— March 27, 2020

What is Cognito in AWS?

Web applications usually allow a valid username and password combination for successful sign in to the application. Modern authentication flows incorporate more approaches to ensure user authentication. When using AWS, this is no exception, thanks to the abilities and features offered b...

Read more
  • AWS
  • AWS Cognito
  • Solutions Architect
Avatar
Andrew Larkin
— March 20, 2020

The 12 AWS Certifications: Which is Right for You and Your Team?

As companies increasingly shift workloads to the public cloud, cloud computing has moved from a nice-to-have to a core competency in the enterprise. This shift requires a new set of skills to design, deploy, and manage applications in cloud computing. As the market leader and most ma...

Read more
  • AWS
  • AWS Certifications
Alisha Reyes
Alisha Reyes
— March 17, 2020

Cloud Academy’s Blog Digest: How Do AWS Certifications Increase Your Employability, How to Become a Microsoft Certified Azure Data Engineer, and more

With everything going on right now, it's likely that the only thing you've been reading lately is related to the coronavirus pandemic. It's important to stay informed during these times, but it's also good to jump into something that can take your mind off of the current situation for j...

Read more
  • AWS
  • Azure
  • blog digest
  • Certifications
  • Cloud Academy
  • programming
  • Security
Avatar
Cloud Academy Team
— March 13, 2020

Which Certifications Should I Get?

As we mentioned in an earlier post, the old AWS slogan, “Cloud is the new normal” is indeed a reality today. Really, cloud has been the new normal for a while now and getting credentials has become an increasingly effective way to quickly showcase your abilities to recruiters and compan...

Read more
  • AWS
  • Azure
  • Certifications
  • Cloud Computing
  • Google Cloud Platform
Alisha Reyes
Alisha Reyes
— March 7, 2020

New on Cloud Academy: Intro to GitOps; AWS Courses; Java, Python, Amazon Linux 2, Ubuntu, & Docker Playgrounds; and much more

New Lab Playgrounds This month, our Content Team released six new "playground labs." Our playground labs provide a safe and secure sandbox environment for you to explore your own ideas, follow along with Cloud Academy courses, or answer your own questions — all without having to instal...

Read more
  • AWS
  • Azure
  • gitops
  • Google Cloud Platform
  • lab playground
  • programming
Alisha Reyes
Alisha Reyes
— March 6, 2020

New on Cloud Academy: Intro to GitOps; AWS Courses; Java, Python, Amazon Linux 2, Ubuntu, & Docker Playgrounds; and much more

New Lab Playgrounds This month, our Content Team released six new "playground labs." Our playground labs provide a safe and secure sandbox environment for you to explore your own ideas, follow along with Cloud Academy courses, or answer your own questions — all without having to instal...

Read more
  • AWS
  • Azure
  • gitops
  • Google Cloud Platform
  • lab playground
  • programming
Patrick Navarro
Patrick Navarro
— March 4, 2020

AWS Certifications: How Do They Increase Your Employability and Progress Your Career?

AWS certifications are no walk in the park. They’re designed to validate in-depth, specialist knowledge and comprehensive experience, often requiring months of dedicated studying to earn even for those already working with the cloud platform. But the rewards that AWS professionals ca...

Read more
  • AWS
  • AWS certification
  • certification
Avatar
Chandan Patra
— February 21, 2020

Elasticsearch vs. CloudSearch: AWS Cloud Search Choices

Elasticsearch vs. CloudSearch: What's the main difference? Let's compare AWS-based cloud tools: Elasticsearch vs. CloudSearch. While both services use proven technologies, Elasticsearch is more popular, open source, and has a flexible API to use for customization; in comparison, CloudS...

Read more
  • AWS
  • Azure
  • cloudsearch
  • elasticsearch
Avatar
Andrew Larkin
— February 13, 2020

Cloud Academy Content Roadmap Updates

Welcome to our Q1 2020 roadmap. This is the content we plan to build over the next three months, between February 1 - and April 30, 2020. Let's look at some of our roadmap highlights. Atlassian Bamboo for CI/CD We had a lot of requests for practical guides on how to apply DevOps tool...

Read more
  • Artificial Intelligence
  • AWS
  • Azure
  • Docker
  • Google Cloud Platform
  • Kubernetes
  • Machine Learning
Alisha Reyes
Alisha Reyes
— February 7, 2020

New on Cloud Academy: Git Labs, CKA and CKAD Lab Challenges, AWS and Azure Learning Paths, AGILE, and Much More

We just kicked off our first Free Weekend of 2020. This means we've unlocked our Training Library for just 72 hours. Until Sunday at 11:59 pm (PST), you can get unlimited access to our industry-leading learning paths, courses, certification prep exams, and our most popular hands-on labs...

Read more
  • agile
  • AWS
  • Azure
  • Google Cloud Platform
  • Linux
  • OWASP
  • programming
  • red hat
  • scrum