- Bundles and Custom Images
- Amazon WorkSpaces Graphics Bundles
- Bring Your Own Windows 7 And Windows 10 Desktop Licenses (BYOL)
- Amazon WorkDocs Sync
- Amazon WorkSpaces Application Manager (Amazon WAM)
- AWS Marketplace for Desktop Apps
- Amazon WorkSpaces Client Applications, Web Access, and User Experience
- Setup and Maintenance
- Pricing and Billing
- Amazon CloudWatch Monitoring
- Printing from Amazon WorkSpaces
Q: What is Amazon WorkSpaces?
Amazon WorkSpaces is a managed desktop computing service running on the AWS cloud. Amazon WorkSpaces allows customers to easily provision cloud-based desktops that allow end-users to access the documents, applications and resources they need on supported devices including Windows and Mac computers, Chromebooks, iPads, Fire tablets, Android tablets, and Chrome and Firefox web browsers. With a few clicks in the AWS Management Console, customers can provision a high-quality cloud desktop experience for any number of users at a cost that is competitive with traditional desktops and half the cost of most Virtual Desktop Infrastructure (VDI) solutions.
Q: What is an Amazon WorkSpace?
An Amazon WorkSpace is a cloud-based virtual desktop that can act as a replacement for a traditional desktop. A WorkSpace is available as a bundle of compute resources, storage space, and software applications that allow a user to perform day-to-day tasks just like using a traditional desktop. A user can connect to a WorkSpace from any supported device using the free Amazon WorkSpaces client application, or using Chrome or Firefox web browsers. Users will connect using credentials set up by an administrator, or using their existing Active Directory credentials if you’ve chosen to integrate your Amazon WorkSpaces with an existing Active Directory domain. Once the user is connected to a WorkSpace they can perform all the usual tasks they would do on a desktop computer.
Q: How can I get started with Amazon WorkSpaces?
To get started with Amazon WorkSpaces, you will need an AWS account. You can use this account to sign into the AWS Management Console and you can then quickly provision Amazon WorkSpaces for yourself and any other users in your organization who might require one. To provision an Amazon WorkSpace, first select a user from your directory. Next, select an Amazon WorkSpaces bundle for the user. The Amazon WorkSpaces bundle specifies the resources you need, which desktop operating system you want to run, and the software applications you want prepackaged. Finally, choose a running mode for their Amazon WorkSpace – pick AlwaysOn if you want to use monthly billing, or AutoStop if you want to use hourly billing. Once your WorkSpace is provisioned, the user will receive an email with instructions for connecting to their WorkSpace. You can use this same process to provision multiple WorkSpaces at the same time.
Q: Which Amazon WorkSpaces bundles are available?
You can find the latest information on Amazon WorkSpaces bundles here.
Q: Which versions of Windows are available for use with Amazon WorkSpaces?
Amazon WorkSpaces offers bundles that come with a Windows 7 or Windows 10 desktop experience, powered by Windows Server 2008 R2 and Windows Server 2016 respectively. If your organization is eligible to bring their own Windows Desktop licenses, you can run the Windows 7 or Windows 10 Enterprise operating system on your Amazon WorkSpaces. See below for more information.
Q: How do I select which desktop experience I want my Amazon WorkSpaces to run?
To select the desktop experience you need for your Amazon WorkSpaces, choose the bundle type that best describes your requirements when you launch new WorkSpaces. For the Windows 7 desktop experience, select bundles that include “Windows 7”. For the Windows 10 desktop experience, select bundles that include “Windows 10”.
Q: Can I migrate users from an Amazon WorkSpaces Windows 7 bundle to a Windows 10 bundle?
No. To offer existing users a Windows 10 desktop experience, you need to delete their existing Amazon WorkSpace and create a new one using a Windows 10 WorkSpaces bundle. To migrate data and documents, we recommend that you use the sync feature available with Amazon WorkDocs. Note that Amazon WorkDocs comes with 50GB of free storage for every Amazon WorkSpace.
Q: How does a user get started with their Amazon WorkSpace once it has been provisioned?
When Amazon WorkSpaces are provisioned, users receive an email providing instructions on where to download the WorkSpaces clients they need, and how to connect to their WorkSpace. If you are not integrating with an existing Active Directory, the user will have the ability to set a password the first time they attempt to connect to their WorkSpace. If the AWS Directory Services AD Connector has been used to integrate with an existing Active Directory domain, users will use their regular Active Directory credentials to log in.
Q: What does a user need to use an Amazon Workspace?
A user needs to have an Amazon WorkSpace provisioned for them, and a broadband Internet connection. To use an Amazon WorkSpaces client application to access their WorkSpace, they will need a supported client device (PC, Mac, iPad, Kindle Fire, or Android tablet), and an Internet connection with TCP ports 443 & 4172, and UDP port 4172 open.
Q: Once users connect to their Amazon WorkSpace can they personalize it with their favorite settings?
An administrator can control what a user can personalize in their WorkSpace. By default, users can personalize their WorkSpaces with their favorite settings for items such as wallpaper, icons, shortcuts, etc. These settings will be saved and persist until a user changes them. If an administrator wishes to lock down a WorkSpace using tools like Group Policy, this will restrict a user’s ability to personalize their WorkSpaces.
Q: Can users install applications on their Amazon WorkSpace?
By default, users are configured as local administrators of their WorkSpaces. Administrators can change this setting and can restrict users’ ability to install applications with a technology such as Group Policy.
Q: Are Amazon WorkSpaces persistent?
Yes. Each WorkSpace runs on an individual instance for the user it is assigned to. Applications and users’ documents and settings are persistent.
Q: How is a user’s data backed up?
The user volume (D:) on the WorkSpace is backed up every 12 hours. In the case of a WorkSpace failure, AWS can restore this volume from the backup. If Amazon WorkDocs Sync is enabled on a WorkSpace, the folder a user chooses to sync will be continuously backed up and stored in Amazon WorkDocs.
Q: Do users need an AWS account?
No. An AWS account is only needed to provision WorkSpaces. To connect to WorkSpaces, users will require only the information provided in the invitation email they will receive when their WorkSpace is provisioned.
Q: If I am located a significant distance from the region where my Amazon WorkSpace is located, will I have a good user experience?
If you are located more than 2000 miles from the regions where Amazon WorkSpaces is currently available, you can still use the service, but your experience may be less responsive. The easiest way to check performance is to use the Amazon WorkSpaces Connection Health Check Website. You can also refer to the Regional Products and Services page for details of Amazon WorkSpaces service availability by region.
Q: Does Amazon WorkSpaces offer a set of public APIs?
Q: Do the Amazon WorkSpaces APIs log actions in AWS CloudTrail?
Yes. Actions on Amazon WorkSpaces performed via the WorkSpaces APIs will be included in your CloudTrail audit logs.
Q: Is there Resource Permission support with the Amazon WorkSpaces APIs?
Yes. You can specify which Amazon WorkSpaces resources users can perform actions on. For details see the documentation.
Q: Do I need to use the AWS Management Console to get started with Amazon WorkSpaces?
Yes. The first time set up for Amazon WorkSpaces relies on the AWS Management Console. Once you have created a directory and registered it with the Amazon WorkSpaces service, you can create and manage WorkSpaces using the Amazon WorkSpaces APIs.
Q: What applications are available with Amazon WorkSpaces Windows 7 bundles?
Amazon WorkSpaces comes with a default set of applications at no additional cost that include Internet Explorer 11, Firefox, and 7-Zip. You can chose to add “Plus” application bundles to your Windows 7 Amazon WorkSpaces bundles which include Microsoft Office Professional 2010 or 2013, Trend Micro Worry-Free Business Security, and WinZip, for an additional monthly fee. Microsoft Office Professional 2016 is available with bundles that offer the Windows 10 desktop experience.
Q: What applications are available with Amazon WorkSpaces Windows 10 bundles?
Amazon WorkSpaces comes with a default set of applications at no additional cost that include Internet Explorer 11, Firefox, and 7-Zip. You can chose to add “Plus” application bundles to your Windows 10 Amazon WorkSpaces bundles which include Microsoft Office Professional 2016, Trend Micro Worry-Free Business Security, and WinZip, for an additional monthly fee. Microsoft Office Professional 2010 and 2013 continue to be available with bundles that offer the Windows 7 desktop experience.
Q: Can I create custom images for Amazon WorkSpaces?
Yes, as an administrator you can create a custom image from a running Amazon WorkSpace. Once you have customized an Amazon WorkSpace with your applications and settings, you can select the WorkSpace in the console and select “Create Image.” This will create an image with your applications and settings. Custom images created from Amazon WorkSpaces Graphics bundles can only be used with Graphics bundles, and custom images created from Value, Standard or Performance bundles can only be used with those bundles. Most Amazon WorkSpace images are available within 45 minutes. See the custom image documentation for more detail.
Q: How do I launch an Amazon WorkSpace from a custom image?
To launch an Amazon WorkSpace from a custom image, you will first need to pair the custom image with a hardware type you want that WorkSpace to use, which results in a bundle. You can then publish this bundle through the console, then select the bundle when launching new WorkSpaces.
Q: What is the difference between a bundle and an image?
An image contains only the OS, software and settings. A bundle is a combination of both that image and the hardware from which a WorkSpace can be launched.
Q: How many custom images can I create?
As an administrator you can create up to 5 custom images per AWS account per region. Please contact us if you need a higher limit.
Q: Can I update the image in an existing bundle?
Yes. You can update an existing bundle with a new image that contains the same tier of software (for example containing the Plus software) as the original image.
Q: What type of Amazon Elastic Block Store (EBS) volumes does Amazon WorkSpaces offer?
All Amazon WorkSpaces launched after 31st January 2017 are built on general purpose solid-state drives (SSD) EBS volumes for both root and user volumes. Amazon WorkSpaces launched prior to 31st January 2017 are configured with EBS magnetic volumes. You can switch your Amazon WorkSpaces using magnetic EBS volumes to SSD EBS volumes by rebuilding them (more information can be found here). You can learn more about SSD EBS volumes here, and magnetic EBS volumes here.
Q: Can I use custom images to launch WorkSpaces with SSD volumes, even if they were created using WorkSpaces with magnetic EBS volumes?
Yes. You can use your custom images to launch WorkSpaces with SSD EBS volumes, even if they were created using WorkSpaces with magnetic EBS volumes.
Q: Do I need to provide an AMI build using WorkSpaces with SSD EBS volumes when using my own Windows desktop licenses (BYOL)?
No. You can use the AMIs you built as part of the BYOL process without any additional changes.
Q: How do I deploy applications to my users?
You have flexibility in how you deploy the right set of applications to users. First, you choose which image type to build from, either basic or Plus, which determines the default applications that will be in the WorkSpaces. Second, you can install additional software on a WorkSpace and create a custom image which can be used to launch more WorkSpaces. For more detail see the bundle documentation.
Q: Which software can I install on an Amazon WorkSpace?
The Amazon WorkSpaces service does not have any technical restrictions on the kind of software that you can install, and any applications that are compatible with the Windows 7 experience provided by Windows Server 2008 R2 should run on your WorkSpaces. We recommend testing any software you would like to deploy on a ‘test’ WorkSpace before delivering it to more users. You are responsible for ensuring that you remain compliant with any licensing restrictions associated with any software you intend to install on a WorkSpace.
Q: Does Amazon WorkSpaces offer GPU-enabled cloud desktops?
Yes. Amazon WorkSpaces offers Amazon WorkSpaces Graphics bundles, available in English and Japanese.
Q: What are Amazon WorkSpaces Graphics bundles?
Amazon WorkSpaces Graphics bundles are Windows Server 2008 R2 based desktops that have a full NVIDIA GPU for graphics intensive applications. The Graphics bundle comes with 8vCPUs, 15GiB of RAM, 4GB of video memory, and 100GBs of storage on the user volume and 100 GBs of general purpose persistent root volume.
Q: What kind of GPU is included with Amazon WorkSpaces Graphics bundles?
The GPU used in Amazon WorkSpaces Graphics bundles is a high-performance NVIDIA GPU with 1,536 CUDA cores and 4GB of video memory. Each Amazon WorkSpaces Graphics bundle has its own GPU.
Q: When would I use Amazon WorkSpaces Graphics bundles?
Amazon WorkSpaces Graphics bundles are designed for engineers and 3D application developers to use as an alternative to expensive graphics-capable workstations. Graphics bundles can be used to run computer-aided design, manufacturing, and engineering software. Additionally, they provide support for OpenGL 4.x, DirectX 10, CUDA, OpenCL, and the GRID SDK for application developers who build 3D capable applications.
Q: Do Amazon WorkSpaces Graphics bundles support a 3D mouse?
The Amazon WorkSpaces Graphics bundles do not currently support a 3D mouse.
Q: What kinds of peripherals can I use with my Amazon WorkSpaces Graphics bundles?
You can use standard QWERTY and Japanese 106/109 keyboards, and most Bluetooth and USB pointing devices with your Amazon WorkSpaces Graphics bundles. You can expect any peripherals that work with Amazon WorkSpaces Value, Standard, and Performance bundles to also work with Amazon WorkSpaces Graphics bundles.
Q: What is the maximum monitor resolution that I can use with my Amazon WorkSpaces Graphics bundles?
Amazon WorkSpaces Graphics bundles support a maximum resolution of 2500x1600, and all VESA compatible resolutions.
Q: How many monitors can I use with my Amazon WorkSpaces Graphics bundles?
Currently you can only use a single monitor with your Amazon WorkSpaces Graphics bundles.
Q: In which AWS Regions can I launch Amazon WorkSpaces Graphics bundles?
You can launch Graphics bundles in all AWS Regions where Amazon WorkSpaces is available.
Q: Can I create a custom image for my Amazon WorkSpaces Graphics bundles?
Yes, you can create a custom image for your Amazon WorkSpaces Graphics bundles. Custom images created from Amazon WorkSpaces Graphics bundles can only be used with Graphics bundles, and custom images created from Value, Standard or Performance bundles can only be used with those bundles.
Q: How do I get started with Amazon WorkSpaces Graphics bundles?
You can launch Amazon WorkSpaces Graphics bundles using the Amazon WorkSpaces Management Console, or the Amazon WorkSpaces API. When launching a new Amazon WorkSpace, simply select the Graphics bundle.
Q: Can I enable hybrid IT scenarios with my Amazon WorkSpaces Graphics bundles?
Yes. You can integrate your Amazon WorkSpaces Graphics bundles with your on-premises environment just as you would with your existing Amazon WorkSpaces. You can connect your Amazon WorkSpaces Graphics bundles to your on-premises Active Directory using the AWS Directory Service. Once domain-joined to your on-premises Active Directory, you can access files from network file shares, print to network printers, and access intranet web sites and applications.
Q: Which operating systems can I use with Amazon WorkSpaces Graphics bundles?
Amazon WorkSpaces Graphics bundles provides users with the Windows 7 desktop experience, running Windows Server 2008 R2. In addition, you can run the Windows 7 Desktop operating system if your organization is eligible to bring their own Windows Desktop license.
Q: How much bandwidth does an Amazon WorkSpaces Graphics bundle consume?
Bandwidth used by an Amazon WorkSpaces Graphics bundle depends on the tasks being performed. If there aren’t many changes taking place on the screen, the bandwidth used is generally less than 300 kbps. If there is context switching between multiple windows, or if 3D models are being manipulated, bandwidth use can increase to several megabits per second.
Q: Can I bring my own Windows Desktop licenses for Amazon WorkSpaces Graphics bundles?
Yes, you can. Please contact us if this is something you’d like to do.
Q: Can I purchase Amazon WorkSpaces Graphics bundles using the monthly billing option?
Yes, you can. Please contact us if this is something you’d like to do.
Yes, you can bring your own Windows 7 and Windows 10 Desktop licenses to Amazon WorkSpaces. Amazon WorkSpaces provides you the ability to run on physically dedicated hardware, enabling you to run the Windows 7 or Windows 10 Desktop operating systems on your Amazon WorkSpaces when you are eligible to bring your own licenses.
Q: Can I bring my own Windows Desktop licenses for Amazon WorkSpaces Graphics bundles?
Yes, you can. Please contact us if this is something you’d like to do.
Q: What versions of Windows desktop licenses can I bring to Amazon WorkSpaces?
If your organization meets the licensing requirements set by Microsoft, you can bring your Windows 7 and Windows 10 Enterprise or Professional licenses to Amazon WorkSpaces. You cannot use Windows OEM licenses for your Amazon WorkSpaces. Please consult with Microsoft if you have any questions about your eligibility to bring your own Windows Desktop licenses.
Q: What benefits are there in bringing my own Windows desktop licenses to Amazon WorkSpaces?
By bringing your own Windows Desktop licenses to Amazon WorkSpaces, you will save $4 per Amazon WorkSpace per month when being billed monthly, and you will save money on the hourly usage fee when being billed hourly (see the Amazon WorkSpaces pricing page for more information). Additionally, you can now use a single golden image to manage your physical and virtual desktop deployments.
Q: What are the requirements for bringing my Windows desktop Licenses to Amazon WorkSpaces?
You need an active and eligible Microsoft Volume Licensing (VL) agreement with Software Assurance contracts to bring your Windows 7 or Windows 10 Desktop licenses to Amazon WorkSpaces. Please consult with your Microsoft representative to confirm your eligibility in bringing your Windows Desktop licenses to Amazon WorkSpaces.
Q: How do I get started with bringing my Windows desktop licenses to Amazon WorkSpaces?
In order to ensure that you have adequate dedicated capacity allocated to your account, please reach out to your AWS account manager or sales representative to get started. Additionally, you can create a Technical Support case with Amazon WorkSpaces to get started with BYOL.
Q: How will I upload my Windows 7 or Windows 10 Desktop image to Amazon WorkSpaces?
Please use the VMImport ImportImage function to import your Windows desktop image and create an Amazon Machine Image (AMI). For additional details on importing your Windows desktop image, please consult our documentation here.
Q: How can I launch Amazon WorkSpaces using my Windows 7 or Windows 10 Desktop image?
In order for you to launch Amazon WorkSpaces using your Windows 7 or Windows 10 Desktop image, you first have to create a custom bundle with the image you imported. Once the new custom bundle has been created, you can launch WorkSpaces from that bundle through the AWS Management Console or using the WorkSpaces CLI or APIs. You can learn more about launching Amazon WorkSpaces using your own Windows 7 or Windows 10 images here.
Q: How will I activate my Windows 7 or Windows 10 Desktop operating system on Amazon WorkSpaces?
You can activate your Windows 7 or Windows 10 Desktop operating system using existing Microsoft activation servers that are hosted in your VPC, or ones that can be reached from the VPC in which Amazon WorkSpaces are launched.
Q: Can I create a new custom image of the Windows 7 or Windows 10 Desktop image uploaded to Amazon WorkSpaces?
Yes. You can use the standard Amazon WorkSpaces image management functionality to further customize the Windows 7 or Windows 10 Desktop image and save it as a new Amazon WorkSpace image in your account.
Q: Can I launch Amazon WorkSpaces from a public bundle in the same directory as my Windows 7 or Windows 10 Desktop WorkSpaces?
No. Your Windows 7 and Windows 10 Desktop WorkSpaces are launched on physically dedicated hardware to enable you to bring your Windows Desktop licenses to Amazon WorkSpaces. Therefore, WorkSpaces launched in a directory marked for dedicated hardware can only be from a custom bundle that has your own Windows 7 or Windows 10 Desktop image. If you wish to launch WorkSpaces from public bundles to users in the same domain, you can create a new AWS AD Connector directory that points to the same Microsoft Active Directory as your Windows 7 and Windows 10 Desktop WorkSpaces, and launch WorkSpaces in that directory as you normally would through the AWS Management Console or the WorkSpaces SDK and CLI.
Q: Can I bring my Windows desktop licenses to all regions where the Amazon WorkSpaces service is available?
Yes. When you communicate with your sales representative or technical support, simply specify the region(s) in which you want to launch Amazon WorkSpaces using your own Windows desktop operating systems.
Q: Would I need to commit to a certain number of Amazon WorkSpaces if I want to bring my own Windows desktop license?
Yes, you need to commit to running 200 Amazon WorkSpaces in a region per month on hardware that is dedicated to you.
Q: How long will it take before I can launch Amazon WorkSpaces using my own Windows desktop licenses and image?
You should expect to be able to launch Amazon WorkSpaces using your Windows 7 or Windows 10 Desktop operating systems within 4 weeks from when you begin the onboarding process.
Q: Will all of my dedicated Amazon WorkSpaces launch in a single AZ?
No. Amazon WorkSpaces launched on dedicated hardware will be balanced across two AZs. You select the AZs for Amazon WorkSpaces when you create the directory in which your Amazon WorkSpaces will be launched, and subsequent launches of Amazon WorkSpaces are automatically load balanced across the AZs selected when you created the directory.
Q: What happens when I terminate Amazon WorkSpaces that are launched on physically dedicated hardware?
You can terminate Amazon WorkSpaces when you no longer need them. You will only be billed for the Amazon WorkSpaces that are running.
Q: What happens to Amazon WorkSpaces that are rebuilt or restarted on physically dedicated hardware?
Amazon WorkSpaces that are rebuilt or restarted can be placed on any available physical server allocated to your account. A re-start or rebuild of an Amazon WorkSpace can result in that instance being placed on a different physical server that has been allocated to your account.
Users sign into their WorkSpace using their own unique credentials, which they can create after a WorkSpace has been provisioned for them. If you have integrated the Amazon WorkSpaces service with an existing Active Directory domain, users will sign in with their regular Active Directory credentials. Amazon WorkSpaces also integrates with your existing RADIUS server to enable multi-factor authentication (MFA).
Q: What is Multi-Factor Authentication (MFA)?
Multi-Factor Authentication adds an additional layer of security during the authentication process. Users must validate their identity by providing something they know (e.g. password), as well as something they have (e.g. hardware or software generated one-time password (OTP).
Q: What delivery methods are supported for MFA?
Amazon supports one time passwords that are delivered via hardware and software tokens. Out of band tokens, such as SMS tokens are not currently supported.
Q: Is there support for Google Authenticator and other virtual MFA solutions?
Google Authenticator can be used in conjunction with RADIUS. If you are running a Linux-based RADIUS server, you can configure your RADIUS fleet to use Google Authenticator through a PAM (Pluggable Authentication Module) library. MFA solutions based on the TOTP (Time-based One-time Password) protocol are not currently supported.
Q: Which Amazon WorkSpaces client applications support Multi-Factor Authentication (MFA)?
MFA is available for Amazon WorkSpaces client applications on the following platforms - Windows, Mac OS X, Chromebooks, iOS, Fire, and Android. MFA is also supported when using Web Access to access Amazon WorkSpaces through Chrome or Firefox web browsers.
Q: What happens if a user forgets the password to access their Amazon WorkSpace?
If either AD Connector or AWS Microsoft AD is used to integrate with an existing Active Directory domain, the user would follow your existing lost password process for your domain, such as contacting an internal helpdesk. If the user is using credentials stored in a directory managed by the WorkSpaces service, they can reset their password by clicking on the “Forgot Password” link in the Amazon WorkSpaces client application.
Q: How will Amazon WorkSpaces be protected from malware and viruses?
You can install your choice of anti-virus software on your users’ WorkSpaces. The Plus bundle options offer users access to anti-virus software, and you can find more details on this here. If you choose to install your own anti-virus software, please ensure that it does not block UDP port 4172, as this will prevent users connecting to their WorkSpaces.
Q: How do I remove a user’s access to their Amazon WorkSpace?
To remove a user’s access to their WorkSpace, you can disable their account either in the directory managed by the WorkSpaces service, or in an existing Active Directory that you have integrated the WorkSpaces service with.
Q: Does WorkSpaces work with AWS Identity and Access Management (IAM)?
Yes. Please see our documentation.
Q: Can I select the Organizational Unit (OU) where computer accounts for my WorkSpaces will be created in my Active Directory?
Yes. You can set a default Organizational Unit (OU) in which computer accounts for your WorkSpaces are created in your Active Directory. This OU can be part of the domain to which your users belong, or part of a domain that has a trust relationship with the domain to which your users belong, or part of a child domain in your directory. Please see our documentation for more details.
Q: Can I use Amazon VPC Security groups to limit access to resources (applications, databases) in my network or on the Internet from my WorkSpaces?
Yes. You can use Amazon VPC Security groups to limit access to resources in your network or the Internet from your WorkSpaces. You can select a default Amazon VPC Security Group for the WorkSpaces network interfaces in your VPC as part of the directory details on the WorkSpaces console. Please see our documentation for more details.
Q: Does Amazon WorkSpaces support encryption?
Yes. Amazon WorkSpaces supports root volume (C: drive) and user volume (D: drive) encryption. Amazon WorkSpaces uses EBS volumes that can be encrypted on creation of a WorkSpace, providing encryption for data stored at rest, disk I/O to the volume, and snapshots created from the volume. Amazon WorkSpaces integrates with the AWS KMS service to allow you to specify the keys you want to use to encrypt the volumes.
Q: Which Amazon WorkSpace bundle types will support encryption?
Encryption is supported on all Amazon WorkSpaces hardware and software bundle types. This includes both Windows 7 and Windows 10 desktop experiences, and the Value, Standard, Performance, and Graphics bundles. It also includes all Plus application bundles. Additionally, any custom bundles will also support encryption.
Q: How can I encrypt a new Amazon WorkSpace?
When creating a new Amazon WorkSpace from the console or the Amazon WorkSpaces APIs, you will have the option to specify which volume(s) you want encrypted along with a key ARN from your KMS keys for encryption. Note that during the launch of a WorkSpace, you can specify whether you want encryption for the user volume, root volume or both volumes, and the key provided will be used to encrypt the volumes specified.
Q: Can I use different keys to encrypt the root and user volumes of a WorkSpace?
The root and user volumes are encrypted using a single key.
Q: Do I need to provide a new KMS key for each WorkSpace that I want to encrypt?
You can use the same KMS key to encrypt the volumes of up to 30 Amazon WorkSpaces.
Q: Can Amazon WorkSpaces create a KMS key on my behalf?
Amazon WorkSpaces creates a default master key upon your first attempt to launch a WorkSpace through the AWS Management Console. You cannot manage the lifecycle of default master keys. To control the full lifecycle of a key, configure WorkSpaces to use a KMS custom customer master key (CMK). To create a KMS custom CMK, visit the KMS console or use KMS APIs to create your own keys. Note that you can use a default key generated by KMS for your WorkSpaces which will be made available to you on your first attempt to launch Amazon WorkSpaces with encryption through the AWS Management Console.
Q: What are the prerequisites for using KMS keys to encrypt Amazon WorkSpaces?
In order to use KMS keys to encrypt Amazon WorkSpaces, the key must not be disabled, and should not have exceeded its limits (learn more about limits here). You also need to have the correct permissions and policies associated with the key to use it for encryption. To learn more about the correct permissions and policies needed on the keys, please refer to our documentation here.
Q: How will I be notified if my KMS key does not meet the pre-requisites outlined above?
When you launch a new WorkSpace with the key specified, the WorkSpaces service will verify if the key is valid and eligible to be used for encryption. If the key is not valid, the launch process will fail quickly and notify you of the error associated with the key. Please note that if you change the key settings while the WorkSpace is being created, there is a chance that provisioning will fail and you will be notified of this failure through the AWS Management Console or through the DescribeWorkSpaces API call.
Q: How will I be able to tell which Amazon WorkSpaces are encrypted and which ones are not?
You will be able to see if a WorkSpace is encrypted or not from the AWS Management Console or using the Amazon WorkSpaces API. In addition to that, you will also be able to tell which volume(s) on the WorkSpace were encrypted, and the key ARN that was used to encrypt the WorkSpace. For example, the DescribeWorkSpaces API call will return information about which volumes (user and/or root) are encrypted and the key ARN that was used to encrypt the WorkSpace.
Q: Can I enable encryption of volumes on a running Amazon WorkSpace?
Encryption of WorkSpaces is only supported during the creation and launch of a WorkSpace.
Q: What happens to a running Amazon WorkSpace when I disable the key in the KMS console?
A running WorkSpace will not be impacted if you disable the KMS key that was used to encrypt the user volume of the WorkSpace. Users will be able to login and use the WorkSpace without interruption. However, restarts and rebuilds of WorkSpaces that were encrypted using a KMS key that has been disabled (or the permissions/policies on the key have been modified) will fail. If the key is re-enabled and/or the correct permissions/policies are restored, restarts and rebuilds of the WorkSpace will work again.
Q: Is it possible to disable encryption for a running Amazon WorkSpace?
Amazon WorkSpaces does not support disabling encryption for a running WorkSpace. Once a WorkSpace is launched with encryption enabled, it will always remain encrypted.
Q: Will snapshots of an encrypted user volume also be encrypted?
Yes. All snapshots of the user volume will be encrypted using the same key that was used to encrypt the user volume of the WorkSpace when it was created. The user volume once encrypted stays encrypted throughout its lifecycle. Please note that Amazon WorkSpaces does not take snapshots of the root volume of a running WorkSpace.
Q: Can I re-build an Amazon WorkSpace that has been encrypted?
Yes. Rebuilds of a WorkSpace will work as long as the key that was used to encrypt the WorkSpace is still valid. The WorkSpace volume(s) stay encrypted using the original key after it has been rebuilt.
Q: Can I create a custom image from a WorkSpace that has been encrypted?
Creating a custom image from a WorkSpace that is encrypted is not supported.
Q: Will the performance of my WorkSpace be impacted because the volume(s) are encrypted?
You can expect a minimum increase in latency on IOPS on encrypted volumes.
Q: Will encryption impact the launch time of an Amazon WorkSpace?
The launch time of a WorkSpace that only requires user volume encryption are similar to those of an unencrypted WorkSpace. The launch time of a WorkSpace that requires root volume encrypt will take several more minutes.
Q: Will encryption be supported for BYOL WorkSpaces?
Yes. Amazon WorkSpaces will support encryption for BYOL WorkSpaces.
Q: Will I be able to use the same KMS key to encrypt Amazon WorkSpaces in a different region?
No. Encrypted resources in one region cannot be used in a different region, because a KMS key belongs to the region in which it was created.
Q: Is there a charge for encrypting volumes on Amazon WorkSpaces?
There is no additional charge for encrypting volumes on WorkSpaces, however you will have to pay standard AWS KMS charges for KMS API requests and any custom CMKs that are used to encrypt WorkSpaces. Please see AWS KMS pricing here. Please note that the Amazon WorkSpaces services makes a maximum of five API calls to the KMS service upon launching, restarting or rebuilding a single WorkSpace.
Q: Can I rotate my KMS keys?
Yes. You can use KMS to rotate your custom CMKs. You can configure a custom CMK that you create to be automatically rotated by KMS on an annual basis. There is no impact to WorkSpaces encrypted before the CMK rotation, they will work as expected.
The Amazon WorkDocs sync client is a client application that you can install on your Amazon WorkSpace, which continuously, automatically, and securely syncs documents from your Amazon WorkSpace to your Amazon WorkDocs location. You can also install the Amazon WorkDocs sync client on a Mac or PC to sync documents across all desktops they may be using. When an Amazon WorkSpace is launched, users will have a link on their desktop so that they can install the Amazon WorkDocs sync client. The client can be downloaded here.
Q: Can I enable or disable Amazon WorkDocs sync for a user’s Amazon WorkSpace?
When you create a directory, or use AD Connector to integrate with an existing Active Directory, you can choose to enable or disable Amazon WorkDocs sync for that directory. Currently you cannot enable or disable Amazon WorkDocs sync on a per-user basis.
Q: How do I synchronize documents between an Amazon WorkSpace and a Mac or Windows PC?
To enable synchronization, all you need to do is install the Amazon WorkDocs sync client on your Amazon WorkSpace and PCs you would like to synchronize with. Once you’ve done this, simply select the folders you want to sync.
Q: Is Single Sign-On (SSO) supported?
Yes. Single Sign-On (SSO) can be enabled so that when users are signed in to their Amazon WorkSpace they will be automatically signed in to their Amazon WorkDocs sync client, and will not be required to provide credentials when they access the web client from their Amazon WorkSpace. You can enable SSO by visiting the AWS Directory Service area of the AWS Management Console, clicking the directory ID link for your directory and selecting the Apps & Services tab. For more information and detailed setup see our documentation.
Amazon WorkSpaces Application Manager (Amazon WAM) offers a fast, flexible, and secure way for you to deploy and manage applications for Amazon WorkSpaces. Amazon WAM accelerates software deployment, upgrades, patching, and retirement by packaging Microsoft Windows desktop applications into virtualized application containers that run as though they are natively installed.
Q: How are Amazon WAM applications delivered to users?
Amazon WAM delivers desktop apps to users' WorkSpaces as virtualized app containers using a unique cloud delivery technology. The applications execute on a WorkSpace from within the virtualized container and provide performance similar to natively-installed applications.
Q: How can I get started with Amazon WAM?
To get started with Amazon WAM, select your level of subscription (Lite or Standard,) build an application catalog in the AWS Management Console and assign applications to your Amazon WorkSpaces users. You can build an application catalog using applications for which you own licenses, proprietary applications built in-house, and applications from the AWS Marketplace for Desktop Apps.
After your catalog is available, you can use the AWS Management Console to assign applications from the catalog to your Amazon WorkSpaces users. Applications from the catalog can be made required or optional. Required applications are automatically installed on the appropriate WorkSpaces; optional applications are made available to users for on-demand installation.
Q: How do I upload my applications to Amazon WAM?
You can package your applications using the Amazon WAM Studio, validate using the Amazon WAM Player, and then upload your applications to Amazon WAM. For more information, see the Amazon WAM User Guide on packaging and validating.
Q: What type of applications can be delivered using Amazon WAM?
Any application compatible with Microsoft Windows 7, Microsoft Windows 8, Microsoft Windows Server 2008 R2, and Microsoft Windows Server 2012 can be delivered to WorkSpaces using Amazon WAM. Both 32-bit and 64-bit applications are supported.
Q: Can I track application use with Amazon WAM?
You can track usage for any applications assigned to users.
Q: In which AWS regions is Amazon WAM available?
Amazon WAM is currently available in the US East (N. Virginia), US West (Oregon), EU (Ireland), Asia Pacific (Sydney), and Asia Pacific (Singapore) AWS regions.
Q: Which Amazon WorkSpaces experiences work with Amazon WAM?
Today you can use Amazon WAM to deploy and manage applications for Amazon WorkSpaces running the Windows 7 desktop experience. Support for Amazon WorkSpaces running the Windows 10 desktop experience will be added at a later time.
Q. Which AWS Directory Service directories does Amazon WAM support?
Q: Do Amazon WorkSpaces need Internet access to use Amazon WAM?
Yes, Amazon WorkSpaces need an Internet connection to receive applications via Amazon WAM.
Q: How do I get Amazon WAM on my users’ Amazon WorkSpaces?
Your users can install the Amazon WAM desktop app on their Amazon WorkSpaces via a shortcut located on the desktop by default.
Q: How do end users access applications that are assigned using Amazon WAM?
Users can open the Amazon WAM desktop app and see all the applications available to them. You can set up applications to be required or optional. Required applications are automatically installed on user's WorkSpace, and optional applications can be installed via the Amazon WAM desktop app. For more information about the Amazon WAM desktop app, see the Amazon WAM User Guide.
Q: How many applications can I add to my Amazon WAM catalog?
There is no limit to the number of applications you can add to your Amazon WAM catalog. However, storage charges apply to applications that you upload to Amazon WAM, after the first 100 GB of storage used for your applications.
Q: How many applications can I deliver to each Amazon WorkSpaces user via Amazon WAM?
You can assign up to 50 applications to each Amazon WorkSpaces user.
Q: Can I use tags to categorize applications in my Amazon WAM catalogs?
Yes, you can assign tags to applications and service-related charges for WAM by simply tagging your Amazon WorkSpaces. To learn more about assigning tags to your Amazon WorkSpaces, follow the steps listed on this web page: Tagging WorkSpaces.
Q: How will I be billed for Amazon WAM?
The Lite plan is available at no cost, and the Standard plan costs $5/user/month for each user enrolled in the WAM Standard plan with one or more applications assigned. There may be a cost for applications from AWS Marketplace for Desktop Applications that users activate.
Q: Can I have users on both the Lite and the Standard plans?
No. You can subscribe to either the Lite or Standard plan, and all users will be on the same plan.
Q: Can I change my subscription plan during the billing period?
Yes. On the “Subscription plan” page” of the WAM console you can upgrade or downgrade your plan and view the feature details for the two subscription plans. You have the opportunity to view the current usage before confirming the upgrade.
Q: What will happen to my applications if I downgrade from the Standard to the Lite plan?
Users will be moved to the most up to date version of applications from AWS Marketplace for Desktop Apps, and will lose access to any applications that you packaged and uploaded to Amazon WAM.
Q: Is there a limit for storage of my app packages?
Both the Lite and Standard plans include 100GB of storage for the apps, and S3 charges will apply for additional storage.
Q: Can I share an Amazon WAM package with another AWS account?
Yes. Packages created and approved by you within your AWS account can be shared with other AWS accounts in the same region. You can set up package sharing via the Packages tab on the Amazon WAM console by adding package permissions to the AWS account to which you wish to share the package.
Q: Can I set limits on the packages that I share with other AWS accounts?
No. At this time, you cannot place any restrictions on packages that are shared.
Q: How do I use an Amazon WAM package that is shared with me?
You can use an Amazon WAM package shared with you by creating an application and assigning the application to your users.
Q: Can I make any changes to a package that has been shared with my account?
No. A package made available to you by another AWS account cannot be modified.
Q: How do I know if I can trust a package that has been shared with my account?
Always verify that your package is shared from a trusted source. Verify the source by validating the AWS account ID and check if it is an account that you trust.
Q: Can I delete an Amazon WAM package?
Yes. You can delete an Amazon WAM package that belongs to your account within an AWS region by launching Amazon WAM Studio in your packaging instance. Once you delete a package, all versions of the package will be deleted. Also, you can only delete packages that don’t have apps assigned or have not been shared with another AWS account. If you have an application created, you will first need to delete the application before you can delete the package. If you have shared a package with another AWS account, you will first need to remove sharing of the package before deleting the package.
Q: What happens to an Amazon WAM package once it is deleted?
Once an Amazon WAM package is deleted, it will no longer be available from within your account. The package will be fully deleted once any accounts you shared the package with have deleted applications using the package.
AWS Marketplace for Desktop Apps is a new category in the AWS Marketplace that can deploy applications to Amazon WorkSpaces through Amazon WAM. The AWS Marketplace for Desktop Apps includes both applications you can purchase on a monthly basis and free apps. You can find applications from developers such as Microsoft, Corel and Foxit and popular open source titles.
Q: How do I use desktop applications from AWS Marketplace?
You can subscribe to applications from the AWS Marketplace for Desktop Apps via Amazon WorkSpaces console. Start by selecting the Application Catalog in Amazon WorkSpaces console, browse and add applications from the AWS Marketplace to your application catalog. Once the applications are in your catalog you can assign the applications to your WorkSpaces users. The applications can then be accessed by users via the Amazon WorkSpaces Application Manager (Amazon WAM) desktop app.
Q: How will I be charged for applications from the AWS Marketplace for Desktop Apps?
You will be charged the price listed on AWS Marketplace for Desktop Apps for each application on a monthly subscription basis. Software subscriptions are billed monthly, even if they are used on Amazon WorkSpaces set to bill hourly. A subscription is activated and charged the first time a user launches an application and will renew monthly until access to the application is removed for that user. Charges for an application are prorated for the remainder of the first month in which a user launches them. Subsequent months are billed for the entire month. Subscriptions that are removed in the middle of a month will not receive a refund for the remainder of the month.
Q: How do I unsubscribe from an application?
To unsubscribe from an application, simply remove the users and groups assigned to use the application. Once this is completed, the application will immediately not be available to your users and there will be no new charges for the application in the following month.
Q: Can Amazon WorkSpaces end users access the AWS Marketplace for Desktop Apps directly?
No, only the administrator of the WorkSpaces account will see the entire AWS Marketplace in the WorkSpaces console. End users will only see the applications you provisioned for them.
Q: Where can I view charges for my application subscriptions from AWS Marketplace for Desktop Apps?
You can view the charges for application subscriptions from AWS Marketplace for Desktop Apps by signing in to the AWS billing console and viewing the AWS Marketplace section in the estimate bill. You can view the applications subscribed, monthly price, and total charge for each application.
Q: How do I get support for the applications I use from AWS Marketplace for Desktop Apps?
After subscribing to the application on AWS Marketplace for Desktop Apps, you can select the application details to view support information. Expand the support information to view details on how to obtain support.
Q: Where can I download the Amazon WorkSpaces client application?
A: You can download the Amazon WorkSpaces client application for free on the client download website.
Q: Can I use any other client (e.g., an RDP client) with Amazon WorkSpaces?
No. You can use any of the free clients provided by AWS, which includes client applications for Windows, Mac OS X, Chromebooks, iOS, Fire tablets, and Android tablets, or Chrome or Firefox web browsers, to access your Amazon WorkSpaces.
Q: Which operating systems are supported by the Amazon WorkSpaces client applications?
Amazon WorkSpaces clients are available for the following operating systems:
- Microsoft Windows 7, Windows 8, and Windows 10
- Apple Mac OS X (10.8.1 and above)
- Google Chrome OS (45 and above)
- Apple iOS (7.0 and above)
- Google Android (4.2 and above)
- Amazon Fire OS 4 and Fire OS 5
Q: Which tablet devices are supported by the Amazon WorkSpaces client application?
Amazon WorkSpaces clients are available for the following devices:
- Apple iPad Pro 12.9-inch and 9.7-inch models
- Apple iPad Mini 2, 3 and 4
- Apple iPad Air and iPad Air 2
- Amazon Fire tablets released after 2012: Fire 7", Fire HD 6/7/8/10, Fire HDX 8.9", Kindle Fire 7", and Kindle Fire HDX 7/8.9
- Samsung and Nexus tablets
While we expect other popular Android tablets running Android version 4.2 to work correctly with the Amazon WorkSpaces client, there may be some that are not compatible. If you are interested in support for a particular device, please let us know via the Amazon WorkSpaces forum.
Q: What is a PCoIP Zero Client?
A PC-over-IP (PCoIP) Zero Client is a single-purpose hardware device that can enable access to Amazon WorkSpaces. Zero Clients include hardware optimization specifically for the PCoIP protocol, and are designed to require very little administration.
Q: Can I use PCoIP Zero Clients with Amazon WorkSpaces?
Yes, Amazon WorkSpaces supports PCoIP Zero Client devices that have the Teradici Tera2 chipset. For a complete list of Zero Clients that are compatible with Amazon WorkSpaces please visit the device finder here (site hosted by Teradici).
Q: Will my Amazon WorkSpace running in AutoStop running mode preserve the state of applications and data when it stops?
Yes. Because AutoStop causes your Amazon WorkSpace to stop, the state of your applications and data will be preserved. When you next connect, your Amazon WorkSpace will resume with all open documents and running programs intact.
Q: How do I resume my Amazon WorkSpace after it stops?
By logging into your Amazon WorkSpace from the Amazon WorkSpaces client application, the service will automatically restart your Amazon WorkSpace. When you first attempt to log in, the client application will notify you that your Amazon WorKSpace was previously stopped, and that your new session will start once your WorkSpace has resumed.
Q: How long does it take for my Amazon WorkSpace to be available once I attempt to log in?
If your Amazon WorkSpace has not yet stopped, your connection is almost instantaneous. If you Amazon WorkSpace has already stopped, in most cases it will be available within sixty to ninety seconds.
Q: Which peripherals can be used with the Amazon WorkSpaces client applications?
Amazon WorkSpaces clients support:
- Keyboard, mouse, and touch input (touch input is only supported on tablet clients)
- Audio output to client device
- Analog and USB headsets
Q: What kind of headsets can be used for audio conversations?
Most analog and USB headsets will work for audio conversations through WorkSpaces. For USB headsets, you should ensure they show up as a playback device locally on your client computer.
Q: Can I use the built in microphone and speakers for making audio calls?
Yes. For the best experience, we recommend using a headset for audio calls. However, you may experience an echo when using the built in microphone and speakers with certain communication applications.
Q: Does Audio-in work with mobile clients such as Android, iOS, and Chromebooks?
Audio-in is supported on the Windows, OSX and iOS clients.
Q: How do I enable Audio-in for my WorkSpaces?
Audio-in is enabled for all new WorkSpaces launches. For existing WorkSpaces, Audio-in can be enabled with a reboot. Enabling the WorkSpaces Audio-in capability requires local logon access inside your WorkSpace. If you have a Group Policy restricting user local logon in your WorkSpace, we will detect it and not apply the Audio-in update to the WorkSpace. You can remove the Group Policy and the Audio-in capability will be enabled after the next reboot.
Q: Should I update my custom images to take advantage of Audio-in?
Yes. We always recommend you refresh your custom images on a regular basis to take advantage of the latest features. WorkSpaces launching from custom images that have not been recently updated may take longer to be available to users. Once a WorkSpace is updated for Audio-In you can use it to create an updated custom image which will include Audio-in support by default.
Q: Does WorkSpaces support devices with high DPI screens?
Yes. The Amazon WorkSpaces desktop client application will automatically scale the in-session display to match the DPI settings of the local device. If desired, it is possible to override the automatic settings by manually selecting a DPI configuration within Windows in an Amazon WorkSpace.
Q: Are dual monitors supported?
Dual monitors are supported on the Amazon WorkSpaces clients for Windows and Mac.
Q: Will the iPad and Android applications support Keyboard/Mouse input?
The iPad client supports keyboard input, and the Android client supports both keyboard and mouse input. While we expect most popular keyboard and mouse devices to work correctly, there may be devices that may not be compatible. If you are interested in support for a particular device, please let us know via the Amazon WorkSpaces forum.
Q: Can I access my Amazon WorkSpaces through a web browser?
Yes, you can use Amazon WorkSpaces Web Access to log in to your Amazon WorkSpace through Chrome or Firefox web browsers. You do not need to install any software, and you can connect from any network that can access the public Internet. Web Access can be accessed here.
Q: What is Amazon WorkSpaces Web Access?
Amazon WorkSpaces Web Access allows you to access your Amazon WorkSpace from Chrome or Firefox running on a computer connected to any network that can access the public Internet. Web Access does not exclude users from using native Amazon WorkSpaces client applications to connect to their WorkSpaces; users can choose between Web Access and native client applications. Web Access is available here.
Q: Which web browsers can I use to access Amazon WorkSpaces Web Access?
Amazon WorkSpaces Web Access works with Google Chrome version 53 and higher, and Firefox version 49 and higher, running on Windows, Max, or Linux. Mobile versions of Chrome and Firefox are not currently supported.
Q: Can I enable Web Access for Non-English based Amazon WorkSpaces?
No. Web Access support is only available on WorkSpaces with English based Windows. You can install language packs onto English based WorkSpaces and have Web Access support. However, WorkSpaces with Windows based on other languages will not have Web Access support through you can still use native clients to access those WorkSpaces.
Q: Do I need to install any additional software in order to access my Amazon WorkSpaces through a web browser?
No, you do not need to install any programs, add-ins, or plugins in order to access your Amazon WorkSpaces through a supported web browser.
Q: How do I get started using Web Access to log in to my Amazon WorkSpaces?
First, your Amazon WorkSpace needs to be enabled for web access. This can be done through the AWS Management Console by your IT administrator. Once this is complete, you can log in using Web Access, which is available here. The first time you log in, you will be asked to enter the registration code that was provided in your welcome email.
Q: How will I know if my Amazon WorkSpace has been enabled for web access?
If your Amazon WorkSpace has been set to block web access, you will receive an error message when you attempt to log in, informing you to contact your system administrator to enable web access.
Q. Can I use Web Access to access my Amazon WorkSpaces on any network?
Yes. You can use Web Access on any network that can access the public Internet. If you can browse the web, then you can connect to your Amazon WorkSpace.
Q: Which Amazon WorkSpaces bundles can be accessed using Web Access?
You can use Web Access to connect to the Value, Standard, and Performance Amazon WorkSpaces bundles running Windows 7 or Windows Server 2008 R2 operating systems. Please note using Web Access to access Amazon WorkSpaces Graphics bundles, or bundles running Windows 10 or Windows Server 2016 operating systems is not currently supported.
Q: Which Amazon WorkSpaces operating systems can be accessed using Web Access?
Web Access can be used to connect to Amazon WorkSpaces running Windows 7 or Windows Server 2008 R2.
Q: What local devices can I use when connecting to my Amazon WorkSpace through Chrome or Firefox?
You will be able to use your mouse and keyboard as input devices. Local peripheral devices—including printers, USB drives, webcams, and microphones—will not be available. Though clipboard redirection will not work across your local operating system and your Amazon WorkSpace, copy and paste operations within your WorkSpace will work.
Q: In which regions is Web Access available?
Amazon WorkSpaces Web Access is available in all regions where you can provision Amazon WorkSpaces. For the complete list, please visit this page.
Q: Do I need to enter a registration code to use Web Access?
The first time you log in using Web Access, you will be asked to enter the registration code that was provided in your welcome email. At the moment, Web Access does not offer the ability to store multiple different registration codes.
Q: When using a web browser to access my Amazon WorkSpace, how can I control my session?
You can use the connection bar along the top of your browser window to control your session. The connection bar allows you to disconnect, enter and exit full screen mode, and send a “Ctrl-Alt-Del” key sequence to the Amazon WorkSpace. It can be pinned in place, or set to hide automatically.
Q: How do I disconnect from my Amazon WorkSpace when accessing it through a web browser?
You can disconnect using the “Disconnect” command in the connection bar, by closing the browser tab, or by quitting the browser program. Web Access does not support reconnecting to your Amazon WorkSpace - you must log in again to reconnect.
Q. Will Amazon WorkSpaces support additional client devices and virtual desktop operating systems?
We continually review our roadmap to see what features we can add to address our customers' requirements. If there is a client device or virtual desktop operating system that you'd like Amazon WorkSpaces to support, please email us with details of your request.
Q: What is the end user experience when Multi-Factor Authentication (MFA) is enabled?
Users will be prompted for their Active Directory username and password, followed by their OTP. Once a user passes both Active Directory and RADIUS validation, they will be logged in to their Amazon WorkSpace. To learn more, visit our documentation.
Q: How can I determine the best region to run my Amazon WorkSpaces?
The Amazon WorkSpaces Connection Health Check Website compares your connection speed to each Amazon WorkSpaces region and recommends the fastest one.
Q: What languages are supported by Amazon WorkSpaces?
Amazon WorkSpaces bundles that provide the Windows 7 desktop experience currently support English (US) and Japanese. Amazon WorkSpaces bundles that provide the Windows 10 desktop experience currently support English (US) only. You can also download and install language packs for Windows directly from Microsoft. For more information, visit this page. Amazon WorkSpaces client applications currently support both English (US) and Japanese.
Yes. The current maintenance window is a four hour period from 00h00 – 04h00 (this time window will be based on the time zone of the AWS region where your Amazon WorkSpaces are located) each Sunday morning. During this time your WorkSpaces may not be available. The maintenance window is currently not configurable.
Q: Will my Amazon WorkSpaces require software updates?
Your Amazon WorkSpaces provide users with the Windows 7 experience, provided by Windows Server 2008 R2. The underlying OS, and any applications installed in the WorkSpace may need updates.
Q: How will my Amazon WorkSpaces be patched with software updates?
You have the ability to control how patching is configured your Amazon WorkSpaces. By default, Windows Update is turned on, but you have the ability to customize these settings, or use an alternative patch management approach if you prefer. Updates are installed at 2am each Sunday.
Q: What action is needed to receive updates for the Amazon WorkSpaces service?
No action is needed on your part. Updates are delivered automatically to your Amazon WorkSpaces during the maintenance window. During the maintenance window, your WorkSpaces may not be available.
Q: Can I turn off the software updates for the Amazon WorkSpaces service?
No. The Amazon WorkSpaces service requires these updates to be provided to ensure normal operation of your users’ WorkSpaces.
Q: I don’t want to have Windows Update automatically update my Amazon WorkSpaces. How can I control updates and ensure they are tested in advance?
You have full control over the Windows Update configuration in your WorkSpaces, and can use Active Directory Group Policy to configure this to meet your exact requirements. If you would like to have advance notice of patches so you can plan appropriately we recommend you refer to Microsoft Security Bulletin Advance Notification for more information.
Q: How are updates for applications installed in my WorkSpaces provided?
For all other applications, updates can be delivered via the automatic update service for each application if one is available. For applications without an automatic update service, you will need to evaluate the software vendor’s recommended updating approach and follow that if necessary.
Q: How can Amazon WorkSpaces be managed?
The WorkSpaces Management console lets you provision, reboot, rebuild, and delete WorkSpaces. To manage the underlying OS for the WorkSpaces, you can use standard Microsoft Active Directory tools such as Group Policy to manage the WorkSpaces. In the case when you have integrated WorkSpaces with an existing Active Directory domain, you can manage your WorkSpaces using the same tools and techniques you are using for your existing on-premises desktops. If you have not integrated with an existing Active Directory, you can set up a Directory Administration WorkSpace to perform management tasks. Please see the documentation for more information.
Q: Can I use tags to categorize my Amazon WorkSpaces?
Yes, you can assign tags to existing Amazon WorkSpaces, or during the launch of new Amazon WorkSpaces. You can assign up to 50 tags (key/value pairs) to each Amazon WorkSpace using the AWS Management Console, the AWS Command Line Interface, or the Amazon WorkSpaces API. These tags automatically get applied to all Amazon WorkSpaces Application Manager (WAM) applications and WAM-related service charges associated with a WorkSpace. To learn more about assigning tags to your Amazon WorkSpaces, follow the steps listed on this web page: Tagging WorkSpaces.
Q: Can I control whether my users can access Amazon WorkSpaces Web Access?
Yes. You can use the AWS Management Console to control whether Amazon WorkSpaces in your directory can be accessed using Web Access, by visit the directory details page. Note: this setting can only be applied to all Amazon WorkSpaces in a directory, not at an individual Amazon WorkSpace level.
Q: What is the difference between rebooting and rebuilding a WorkSpace?
A reboot is just the same as a regular operating system (OS) reboot. A rebuild will retain the user volume on the WorkSpace (D:) but will return the WorkSpace to its original state (any changes made to the system drive (C:) will not be retained).
Q: How do I remove an Amazon WorkSpace I no longer require?
To remove a WorkSpace you no longer require, you can “delete” the Workspace. This will remove the underlying instance supporting the WorkSpace and the WorkSpace will no longer exist. Deleting a WorkSpace will also remove any data stored on the volumes attached to the WorkSpace, so please confirm you have saved any data you must keep prior to deleting a WorkSpace.
Q: Can I provide more than one Amazon Workspace per user?
No. You can currently only provide one WorkSpace for each user.
Q: How many WorkSpaces can I launch?
While there is no limit to the number of WorkSpaces, we have a default limit of up to 20 WorkSpaces per AWS account per region. New AWS accounts may start with limits that are lower than the limits described here. Please contact us if you need a higher limit.
Q: Is there a minimum number of Amazon WorkSpaces or users I must provision?
No. There is no minimum requirement.
Q: What is the maximum network latency recommended while accessing a Workspace?
While the remoting protocol has a maximum round trip latency recommendation of 250 ms, the best user experience will be achieved at less than 100 ms.
Q: Does WorkSpaces need any Quality of Service configurations to be updated on my network?
If you wish to implement Quality of Service on your network for WorkSpaces traffic, you should prioritize WorkSpaces’ interactive video stream which is comprised of real time traffic on UDP port 4172. If possible, this traffic should be prioritized just after VoIP to provide the best user experience.
Q: Which AWS regions does Amazon WorkSpaces support?
Please refer to the Regional Products and Services page for details of Amazon WorkSpaces service availability by region.
Q: Is MFA on Amazon WorkSpaces available in my region?
Support for MFA is available in all AWS Regions where Amazon WorkSpaces is offered.
Q: What are the prerequisites for setting up a PCoIP Zero Client?
Zero Clients should be updated to firmware version 4.6.0 (or newer). You will need to run the PCoIP Connection Manager to enable the clients to successfully connect to Amazon WorkSpaces. Please consult the Amazon WorkSpaces documentation for a step by step guide on how to properly setup the PCoIP Connection Manager, and for help on how to find and install the necessary firmware required for your Zero Clients
Q: How do I get support with Amazon WorkSpaces?
You can pay for your Amazon WorkSpaces either by the hour, or by the month. You only pay for the WorkSpaces you launch, and there are no upfront fees and no term commitments. The fees for using Amazon WorkSpaces include use of both the infrastructure (compute, storage, and bandwidth for streaming the desktop experience to the user) and the software applications listed in the bundle.
Q: How much does an Amazon WorkSpace cost?
Please see our pricing page for the latest information.
Q: Is there a price difference between Amazon WorkSpaces Windows 7 and Windows 10 bundles?
No. There is no price difference between Amazon WorkSpaces Windows 7 and Windows 10 bundles. Note, however, that there is an additional charge for the Plus versions of both Windows 7 and Windows 10 bundles.
Q: Can I pay for my Amazon WorkSpaces by the hour?
Yes, you can pay for your Amazon WorkSpaces by the hour. Hourly pricing is available for all WorkSpaces bundles, and in all AWS regions where Amazon WorkSpaces is offered.
Q: How does hourly pricing work for Amazon WorkSpaces?
Hourly pricing has two components: an hourly usage fee, and a low monthly fee for fixed infrastructure costs. Hourly usage fees are incurred only while your Amazon WorkSpaces are actively being used, or undergoing routine maintenance. When your Amazon WorkSpaces are not being used, they will automatically stop after a specified period of inactivity, and hourly metering is suspended. When your Amazon WorkSpaces resume, hourly charges begin to accrue again.
Q: How do I get started with hourly billing for my Amazon WorkSpaces?
To launch an Amazon WorkSpace to be billed hourly, simply select a user, choose an Amazon WorkSpaces bundle (a configuration of compute resources and storage space), and specify the AutoStop running mode. When your Amazon WorkSpace is created, it will be billed hourly.
Q: What is the difference between monthly pricing and hourly pricing for Amazon WorkSpaces?
With monthly billing, you pay a fixed monthly fee for unlimited usage and instant access to a running Amazon WorkSpace at all times. Hourly pricing allows you to pay for your Amazon WorkSpaces by the hour and save money on your AWS bill when your users only need part-time access to their Amazon WorkSpaces. When your Amazon WorkSpaces being billed hourly are not being used, they automatically stop after a specified period of inactivity, and hourly usage metering is suspended.
Q: How do I select hourly billing or monthly billing for my Amazon WorkSpaces?
To make hourly billing possible, Amazon WorkSpaces now operates in two running modes – AutoStop and AlwaysOn. The AutoStop running mode allows you to pay for your Amazon WorkSpaces by the hour. The AlwaysOn running mode is used when paying a fixed monthly fee for unlimited usage of your Amazon WorkSpaces. You can easily choose between monthly and hourly billing by selecting the running mode when you launch Amazon WorkSpaces through the AWS Management Console, the Amazon WorkSpaces APIs, or the Amazon WorkSpaces Command Line Interface. You can also switch between running modes for your Amazon WorkSpaces at any time.
Q: When do I incur charges for my Amazon WorkSpace when paying by the hour?
Hourly usage fees start accruing as soon as your Amazon WorkSpace is running. Your Amazon WorkSpace may resume in response to a login request from a user, or to perform routine maintenance.
Q: When do I stop incurring charges for my Amazon WorkSpaces when paying by the hour?
Hourly usage charges are suspended when your Amazon WorkSpaces stop. AutoStop automatically stops your WorkSpaces a specified period of time after users disconnect, or when scheduled maintenance is completed. The specified time period is configurable and is set to 60 minutes by default. Note that partial hours are billed as a full hour, and the monthly portion of hourly pricing does not suspend when your Amazon WorkSpaces stop.
Q: Can I force hourly charges to suspend sooner?
You can manually stop Amazon WorkSpaces from the AWS Management Console, or by using the Amazon WorkSpaces APIs. To stop the monthly fee associated with your hourly Amazon WorkSpaces, you need to remove the Amazon WorkSpaces from your account (note: this also deletes all data stored in those Amazon WorkSpaces).
Q: Can I switch between hourly and monthly billing?
Yes, you can switch from hourly to monthly billing for your Amazon WorkSpaces at any time by switching the running mode to AlwaysOn in the AWS Management Console, or through the Amazon WorkSpaces APIs. When you switch, billing immediately changes from hourly to monthly, and you are charged a prorated amount at the monthly rate for the remainder of the monthy, along with the low monthly and hourly usage fees already billed for the month. Your Amazon WorkSpaces will continue to be charged monthly unless you switch the running mode back to AutoStop.
You can switch from monthly to hourly billing by setting the running mode to AutoStop in the AWS Management Console or through the Amazon WorkSpaces APIs. Switching from monthly to hourly billing will take effect the following month as you will have already paid for your Amazon WorkSpaces for that month. Your Amazon WorkSpaces will continue to be charged hourly unless you switch the running mode back to AlwaysOn.
Q: If I don’t use my Amazon WorkSpace for the full month, are the fees prorated?
If you’re paying for your Amazon WorkSpaces monthly, your Amazon WorkSpaces are charged for the full month’s usage. If you’re paying hourly (AutoStop running mode), you are charged for the hours during which your Amazon WorkSpaces are running or undergoing maintenance, plus a monthly fee for fixed infrastructure costs. In both cases, the monthly fee is prorated in the first month only.
Q: Will I be charged the low monthly fee associated with hourly billing if I don’t use my Amazon WorkSpaces in a given month?
Yes, you will be charged a small monthly fee for the Amazon WorkSpaces bundle you selected. If you’ve chosen an Amazon WorkSpaces Plus bundle, you will be charged for the software subscription as well. You can find the monthly fees for all Amazon WorkSpaces on the pricing page here.
Q: How are the Plus software bundles charged when I pay hourly for my Amazon WorkSpaces?
Plus bundles are always charged monthly, even if you’re paying for your Amazon WorkSpaces by the hour. If you selected a Plus bundle when you launched your WorkSpaces, you will incur the listed fee for the Plus software bundle even if you do not use those Amazon WorkSpaces in a particular month.
Q: Can I purchase Amazon WorkSpaces Graphics bundles using the monthly billing option?
Yes, you can. Please contact us if this is something you’d like to do.
Q: Will I be able to monitor how many hours my Amazon WorkSpaces have been running?
Yes, you will be able to monitor the total number of hours your Amazon WorkSpaces have been running in a given period of time through the Amazon CloudWatch “UserConnected” metric.
Q: Does Amazon WorkSpaces pricing include bandwidth costs?
Amazon WorkSpaces pricing includes network traffic between the user’s client and their WorkSpace. Web traffic from WorkSpaces (for example, accessing the public Internet, or downloading files) will be charged separately at current AWS bandwidth rates.
Q: How will I be charged for Amazon WorkSpaces that I launch that are based on a custom image?
There is no additional charge for Amazon WorkSpaces created from custom images. You will be charged the same as the underlying bundles on which the customized images are based.
Q: Can I use custom images for Amazon WorkSpaces that are billed hourly?
Yes. You can launch Amazon WorkSpaces billed hourly from images that you create and upload. There is no additional charge for Amazon WorkSpaces launched from custom images. You will be charged the same as the underlying bundles on which the customized images are based.
Q: Is there a charge to use Amazon WorkSpaces client applications?
The Amazon WorkSpaces client applications are provided at no additional cost, and you can install the clients on as many devices as you need to. You can access these here.
Q: Is there an additional charge to access Amazon WorkSpaces using Web Access?
There is no additional charge to access Amazon WorkSpaces using Web Access. For Amazon WorkSpaces set to bill hourly, you will keep getting billed for the time you leave a browser tab open with an actively running Amazon WorkSpace.
Q: Can I use tags to obtain usage and cost details for Amazon WorkSpaces, Amazon WorkSpaces Application Manager (WAM), and WAM applications on my AWS monthly billing report?
Yes. By setting tags to appear on your monthly Cost Allocation Report, your AWS monthly bill will also include those tags. You can then easily track costs according to your needs. To do this, first assign tags to your Amazon WorkSpaces by following the steps listed on this web page: Tagging WorkSpaces. Next, select the tag keys to include in your cost allocation report by following the steps listed on this web page: Setting Up Your Monthly Cost Allocation Report.
Q: Are there any costs associated with tagging Amazon WorkSpaces?
There are no additional costs when using tags with your Amazon WorkSpaces.
Q: What does the Amazon WorkSpaces Application Manager (Amazon WAM) cost?
Amazon WAM is available in two versions - lite or standard. The Amazon WAM lite subscription is available at no charge, and the Amazon WAM standard subscription costs $5/user/month. You can learn more about Amazon WAM here.
Q: Can I pay for Amazon WAM on an hourly basis?
Amazon WAM is not available for hourly billing. You will still be charged monthly for Amazon WAM usage, even if you’re using Amazon WAM to deliver applications to an Amazon WorkSpace being billed hourly.
Q: Do I have to pay to use the Amazon WAM Studio or Amazon WAM Player?
No. There is no additional charge for using the Studio or Player. You will be charged for AWS resources such as the Amazon EC2 instance hours, EBS storage, and bandwidth when using the Studio to package your applications for Amazon WAM.
Yes, you can configure a WorkSpaces Client app to use an HTTPS proxy. Please see our documentation for more information.
Q: Can I connect Amazon WorkSpaces to my VPC?
Yes. The first time you connect to the WorkSpaces Management Console, you can choose an easy ‘getting started’ link that will create a new VPC and two associated subnets for you as well as an Internet Gateway and a directory to contain your users. If you choose to access the console directly, you can choose which of your VPCs your WorkSpaces will connect to. If you have a VPC with a VPN connection back to your on-premises network, then your WorkSpaces will be able to communicate with your on-premises network (you retain the usual control you have over network access within your VPC using all of the normal configuration options such as security groups, network ACLS, and routing tables).
Q: Can I connect to my existing Active Directory with my Amazon WorkSpaces?
Yes. You can use AD Connector or AWS Microsoft AD to integrate with your existing on-premises Active Directory.
Q: Will my Amazon WorkSpaces be able to connect to the Internet to browse websites and download applications?
Yes. You have full control over how your Amazon WorkSpaces connect to the Internet based on regular VPC configuration. Depending on what your requirements are you can either deploy a NAT instance for Internet access, assign an Elastic IP Address (EIP) to the Elastic Network Interface (ENI) associated with the WorkSpace, or your WorkSpaces can access the Internet by utilizing the connection back to your on-premises network.
Q: Can my Amazon WorkSpaces connect to my applications that are running in Amazon EC2 such as a file server?
Yes. Your WorkSpaces can connect to applications such as a fileserver running in Amazon EC2 (both “Classic” and VPC networking environments). All you need to do is ensure appropriate route table entries, security groups and network ACLs are configured so that the WorkSpaces can reach the EC2 resources you would like them to be able to connect to.
Q: What are the pre-requisites for enabling MFA on Amazon WorkSpaces?
To enable MFA on WorkSpaces, you will need to configure AD Connector, and have an on-premises RADIUS server(s). Your on-premises network must allow inbound traffic over the default RADIUS server port (1812) from the AD Connector server(s). Additionally, you must ensure that usernames match between Active Directory and your RADIUS server. To learn more, visit our documentation.
Each user you provision a WorkSpace for needs to exist in a directory, but you do not have to provision a directory yourself. You can either have the WorkSpaces service create and manage a directory for you and have users in that directory created when you provision a WorkSpace. Alternatively, you can integrate WorkSpaces with an existing, on-premises Active Directory so that users can continue to use their existing credentials meaning that they can get seamless applications to existing applications.
Q: If I use a directory that the Amazon WorkSpaces service creates for me, can I configure or customize it?
Yes. Please see our documentation for more details.
Q: Can I integrate Amazon WorkSpaces with my existing on-premises Active Directory?
Yes. You can use AD Connector or AWS Microsoft AD to integrate with your existing on-premises Active Directory.
Q: How do I integrate Amazon WorkSpaces with my on-premises Microsoft Active Directory?
There are two ways you can integrate Amazon WorkSpaces with your on-premises Microsoft Active Directory (AD): you can set up an interforest trust relationship with your AWS Microsoft AD domain controller, or you can use AD Connector to proxy AD authentication requests.
To configure an interforest trust relationship between your on-premises Microsoft AD and your AWS Microsoft AD please see the documentation here. To configure AD Connector, please see the documentation here.
Once a trust is established, you can select the trust (domain?) where your user accounts reside directly in the Amazon WorkSpaces console, and proceed to provisioning WorkSpaces for your users. Please note that usernames across domains need to be unique per instance of AWS Microsoft AD.
Q: There are two options for integrating Amazon WorkSpaces with my on-premises Microsoft Active Directory. Which one should I use?
You can integrate Amazon WorkSpaces with your on-premises Microsoft Active Directory (AD) either by setting up an interforest trust relationship with your AWS Microsoft AD domain controller, or by using AD Connector to proxy AD authentication requests.
When using interforest trust, you only need a single trust relationship between your on-premises AD and your AWS Microsoft AD domain controller. You can assign Amazon WorkSpaces to users in any of your on-premises domains, and AWS Microsoft AD automatically discovers and routes authentication requests to the correct domain controller. This option works well when your environment consists of multiple on-premises Microsoft AD domains.
When using AD Connector, a separate AD Connector is required for each of your on-premises Microsoft AD domains with users that will need WorkSpaces assigned to them. Using AD Connector works well for environments with a single on-premises domain, or for proof-of-concept projects.
For more information, please visit this page.
Q: Can I use the Amazon WorkSpaces APIs to create new WorkSpaces for users across domains when I have an interforest trust relationship established with AWS Microsoft AD?
Yes. When using the Amazon WorkSpaces API to launch WorkSpaces, you will need to specify the domain name as part of the username, in this format: “NETBIOS\username” or “corp.example.com\username”. For more information, please visit this page.
Q: Can I apply the same Group Policy object settings from my on-premises Microsoft Active Directory to Amazon WorkSpaces?
Yes. If you’re using an interforest trust relationship between your on-premises Microsoft AD and your AWS Microsoft AD domain controller, you will need to ensure that your Group Policy object (GPO) settings are replicated across domains before they can be applied to Amazon WorkSpaces. If you are using AD Connector, your GPO settings will be applied to your WorkSpaces much like any other computer in your domain.
Q: Can I apply Active Directory policies to my Amazon WorkSpaces using the directory that the WorkSpaces service creates for me?
Yes. Please see our documentation for more details.
Q: What happens to my directory when I remove all of my Amazon WorkSpaces?
If there are no WorkSpaces being used with your Simple AD or AD Connector for 30 consecutive days, you will be charged for this directory as per the AWS Directory Service pricing terms. If you delete your Simple AD or AD Connector you can always create a new one when you want to start using WorkSpaces again.
Q: Which AWS Directory Services support the use of PCoIP Zero Clients?
PCoIP Zero Clients can be used with the AD Connector and Simple AD directory services from AWS. Currently, Zero Clients cannot be used with the AWS Directory Service for Mirosoft Active Directory.
You can use Amazon CloudWatch metrics for Amazon WorkSpaces to review health and connection metrics for individual WorkSpaces and all WorkSpaces belonging to a directory. You can set up CloudWatch alarms on these metrics to be alerted about changes to WorkSpaces health, or about issues your users may have connecting to their WorkSpaces.
Q: Will I be able to monitor how many hours my Amazon WorkSpaces have been running?
Yes, you will be able to monitor the total number hours your Amazon WorkSpaces has been running in a given period of time through Amazon CloudWatch “UserConnected” metric.
Q: In what regions can I use Amazon WorkSpaces with CloudWatch metrics?
CloudWatch metrics for Amazon WorkSpaces is supported in all AWS regions in which Amazon WorkSpaces is available.
Q: What does it cost?
There is no additional cost for using Basic CloudWatch metrics with WorkSpaces via the CloudWatch console. There may be additional charges for setting up CloudWatch alarms and retrieving CloudWatch metrics via APIs. Please see CloudWatch pricing for more information.
Q: How do I get started?
Basic CloudWatch metrics are enabled by default for all your WorkSpaces. Visit the AWS Management Console to review the metrics and set up alarms.
Q: What metrics are supported for the Amazon WorkSpaces client application and PCOIP Zero Clients?
Please see the documentation for more information on Amazon CloudWatch metrics with Amazon WorkSpaces.
Q: What metrics are supported for Amazon WorkSpaces Web Access usage?
The following metrics are currently supported for reporting on Amazon WorkSpaces Web Access usage:
Please see the documentation for more information on Amazon CloudWatch metrics with Amazon WorkSpaces.
Yes, Amazon WorkSpaces supports local printers, network printers, and cloud printing services.
Q: Which printer is set as the default in my Amazon WorkSpace?
If you have a local printer configured on the Windows or Mac computer you use to connect to your Amazon WorkSpace, then that printer will be set as the default printer when you connect to your WorkSpace.
Q: How do I print to my local printer?
If you have a local printer configured, it will be selected by default. If not, you will need to configure a local printer outside of your WorkSpace. Once this is done, select your local printer from the print menu, and select print.
Q: Why can’t I see my local printer from the printing menu?
Most printers are already supported by Amazon WorkSpaces. If your printer is not recognized, you may need to install the appropriate device driver on your WorkSpace.
Q: How do I print to a network printer?
Any printer which is on the same network as your Amazon WorkSpace and is supported by Windows Server 2008 R2 can be added as a network printer. Once a network printer is added, it can be selected for printing from within an application.
Q: Can I use my Amazon WorkSpace with a cloud printing service?
You can use cloud printing services with your WorkSpace including, but not limited to, Cortado ThinPrint,® and Google Cloud Print.
Q: Can I print from my tablet or Chromebook?
The Amazon WorkSpaces clients for tablets and Chromebook support cloud printing services including, but not limited to, Cortado ThinPrint® and Google Cloud Print. Local and network printing are not currently supported.