Desktop and Application Streaming

Tag: EUC

How to use Okta claims with application entitlements for Amazon AppStream 2.0

This blog post shows you how to use Okta claims to configure application entitlements for your Amazon AppStream 2.0 stacks. Customers use Amazon AppStream 2.0 to manage applications centrally, and stream them to their end users. With , you control access to specific applications in the AppStream 2.0 application catalog with SAML assertions. In addition, […]

Use Amazon AppStream 2.0 application entitlements with Azure AD

This blog post shows you how to use application entitlements with Azure Active Directory (Azure AD) for your AppStream 2.0 stacks. Customers use Amazon AppStream 2.0 to manage applications centrally, and stream them to their end users. With application entitlements, you can control access to specific applications in the AppStream 2.0 application catalog based on […]

Optimize User Experience with latency-based routing for Amazon AppStream 2.0

This blog post walks you through the configuration of deploying a multi-Region AppStream 2.0 workload that can automatically direct users to the AppStream 2.0 Region with the lowest latency for streaming sessions when connecting with a third-party SAML 2.0 identity provider. If the AppStream 2.0 deployment they use for their role is tied to a […]

Cross-Region redirection with Geo Targetly and Amazon AppStream 2.0

You can setup cross-Region redirection with services like Geo Targetly to automatically redirect Amazon AppStream 2.0 users to the AppStream stacks that are closest to their current location. If the AppStream 2.0 deployment they use for their role is tied to a specific Region, users can experience high latency when traveling far distances from the […]

OneLogin SSO with Amazon AppStream 2.0

Amazon AppStream 2.0 supports identity federation to AppStream 2.0 stacks through Security Assertion Markup Language 2.0 (SAML 2.0). This feature offers your users the convenience of access to their AppStream 2.0 applications using their existing identity credentials. You also have the security benefit of identity authentication by your IdP. By using your IdP, you can […]

Set up multi-factor authentication with OneLogin for Amazon WorkSpaces

In this blog, I walk you through configuring Amazon WorkSpaces multi-factor authentication (MFA) with OneLogin. Solution overview The steps to work through this blog are: Configure OneLogin RADIUS for use with Amazon WorkSpaces. Configure Active Directory Connector for MFA. Test logon. Prerequisites: This post assumes you have the following. A OneLogin account. OneLogin Active Directory […]

Create a Single Identity Provider for all your Amazon AppStream 2.0 Stacks with Azure AD

Customers use Amazon AppStream 2.0 to centrally manage applications and stream them to their end users. Organizations have multiple stacks associated with different fleets to separate workloads based on underlying resources, applications, or different user permissions. Administrators want a way to manage permissions for multiple stacks without having to create an IAM identity provider for […]

Active Directory Group Membership Based AppStream 2.0 Application Targeting

The default behavior of an Amazon AppStream 2.0 Stack is to present all the applications to the end user that were added to the application catalog by the administrator creating the image. Customers accustomed to targeting individual applications to end users based on Active Directory group membership can also continue to do so using the […]

Enabling Federation with SimpleSAMLphp and Amazon AppStream 2.0

SimpleSAMLphp is an open-source project written in native PHP that deals with authentication for SAML 2.0 as a Service Provider and as an Identity Provider. You can use single sign-on with Amazon AppStream 2.0 with many identity services that are compliant with Security Assertion Markup Language 2.0 (SAML 2.0). This post explains how to configure federated user […]

DataScientist or data analyst connects to a custom URL. URL takes them to identity provider, which challenges them with multi-factor authentication. Once authenticated, they assume a role in AWS which grants them access to AppStream 2.0. Once they connect to AppStream 2.0, they launch their streaming application. And finally, the application gives them access to tools that they use to access the data in the isolated environment.

How Amazon Uses Amazon AppStream 2.0 to Provide Data Scientists and Analysts with Access to Sensitive Data

The Challenge On February 28th 2020, due to the COVID-19 pandemic, Amazon announced that we had taken steps to protect the health of our employees and communities. This included canceling large events, moving stakeholder meetings online, and pausing tours of fulfillment centers. As of this post, Amazon has continued to invest more than $8 billion […]