Virtual Computing Environment Domain Join Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of joining a virtual computing environment to a managed directory is labor-intensive and prone to errors, increasing costs and complexity for administrators.

Innovation Solution

A method where an administrator requests provisioning of a virtual computing environment with domain join credentials, allowing users to access the environment using their own domain credentials, eliminating the need for manual administrator intervention and exposing credentials to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual domain join process is used with administrator credentials, then the virtual computing environment can be joined to the managed directory, but the process becomes labor intensive and error prone

Engineering Contradiction:
Improvedomain join accuracyVSAvoidadministrator workload
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service domain joining where users can automatically join the virtual computing environment to the managed directory using their own credentials without requiring administrator intervention. The virtual computing environment service automatically provisions credentials and performs the domain join operation, eliminating manual administrator workload while maintaining reliable and error-free joining process.

Inventive Principle:
Principle #25Self-service

2Reliability

If administrator uses credentials to join virtual computing environment to managed directory, then domain join is achieved, but credentials are exposed to administrators increasing security risks

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and removes the credential exposure risk from the administrator by implementing automatic credential provisioning. The virtual computing environment service automatically generates and manages credentials without requiring administrators to handle or expose them. Users receive their own credentials through the system, eliminating the security risk associated with administrators exposing credentials while maintaining proper authentication mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If manual domain join process is implemented, then the virtual computing environment can access the managed directory, but the process is time consuming and reduces productivity

Engineering Contradiction:
Improvedirectory access capabilityVSAvoidenvironment provisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by automatically provisioning credentials and configuring domain join settings before the user needs to access the managed directory. The virtual computing environment service pre-configures everything needed for seamless directory access, eliminating the need for time-consuming manual setup operations while ensuring reliable directory access capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9853978B2Domain join and managed directory support for virtual computing environments
Publication Date: 2017.12.26 AMAZON TECH INC
  • US9853978B2 patent drawing
  • US9853978B2 patent drawing
  • US9853978B2 patent drawing

AI summary

A virtual computing environment service may receive a request from a customer to provision a virtual computing environment and join the virtual computing environment to a managed directory. The virtual computing environment service may provision the virtual computing environment and uses a set of administrator credentials from the customer and a set of credentials corresponding to the environment to access the managed directory and request joining of the environment to the managed directory. In response, the managed directory may create a computer account corresponding to the environment and which enables the environment to be used to access the managed directory. The virtual computing environment service may then enable the customer to specify one or more users that may utilize the virtual computing environment to access the managed directory.