Deploy a new Active Directory domain controller 2016, to setup a new domain/forest or add to an existing domain.
Provide Active Directory and DNS services to servers, users and applications running in AWS
Active Directory Features
The perfect solution for providing Active Directory domain services to your servers in AWS
Enable Hybrid Active Directory using existing AD with your AWS tenant
Provide Group Polices (GPOs) to your servers, Users in AWS
Provide AD authentication services to your applications
Extend onprem Active Directory into AWS. Replicate onprem AD to new AD servers in AWS
Provide DNS name resolution to your servers & applications in AWS
Provide Single Sign On (SSO) for users logging into servers, services in AWS using Active Directory
This Windows Server 2016 VM comes pre loaded with the Active Directory Domain Services role, DNS server role, remote administration tools for AD, DNS and the required Powershell modules.
Upon powering up the ec2 VM the first time launch the DC promo wizard from server manager and start the setup of your new domain controller. Choose to setup a new domain or join this DC to an existing Active Directory Domain
Highlights
Provide Active Directory domain services to your servers, applications and users in AWS
Provide AD Group Policies (GPOs) to your servers in AWS. Secure your server logins and restrict server operating systems using Active Directory group policies.
Enable Hybrid Active Directory with your AWS environment or Azure AD
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this Active Directory Domain Controller 2016 image, with no upfront commitment. Pricing is not a set of feature tiers. Instead, you pick from a wide range of EC2 instance types, and your hourly rate depends on the instance you choose. Smaller instances (such as t2 and t3 sizes) carry lower hourly costs, while larger compute, memory, GPU, and bare-metal instances (such as x1e, u-metal, and p3 sizes) cost more per hour. Your total cost scales with instance size and hours run. Software function stays the same across all instances.
Top-of-mind questions for buyers
What does one hourly unit cover for a given EC2 instance type?
One unit is one running instance of the Domain Controller 2016 image for one hour on the EC2 type you select. Each instance you launch is billed separately per hour. The software function stays identical no matter which instance type you pick.
Am I charged when the domain controller instance is stopped, such as a standby DR node?
Hourly software charges apply only while the instance runs. A fully stopped instance does not accrue software charges. Stopped instances may still incur underlying AWS storage fees for their attached disks. If you keep a standby domain controller powered off, you avoid the hourly software cost.
If I run several domain controllers for replication, how does that affect my bill?
Each domain controller runs on its own instance and is billed separately per hour. Running multiple controllers for replication multiplies the hourly software cost by the number of active instances. Your total is the sum of each instance's hourly rate times its running hours.
cloudinfrastructureservices.co.uk
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Latest OS Patches installed. Simply run Windows update to install the latest Microsoft patches
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Deployment of Active Directory Domain Controller 2016 with capability to establish new domain/forest or integrate with existing domains for centralized identity management
DNS Server Role
Integrated DNS server role for providing name resolution services to servers and applications running in AWS infrastructure
Group Policy Management
Group Policy Objects (GPOs) functionality to enforce security policies, restrict server operating systems, and manage server login configurations across AWS environment
Hybrid Active Directory Integration
Support for hybrid Active Directory setup enabling synchronization and replication between on-premises Active Directory and AWS-deployed domain controllers
Single Sign-On Authentication
Single Sign-On (SSO) capability for user authentication to servers and services in AWS using Active Directory credentials
Cloud Directory Identity Management
Centralize access across all identities with integrations to AWS Identity Center, Google Workspace, Microsoft 365, Active Directory, HRIS platforms, and network infrastructure resources
Single Sign-On and Multi-Factor Authentication
Frictionless, secure access to AWS resources and over 900 pre-built applications with automated user provisioning to Amazon IAM Identity Center and group-based permissions
Cross-Operating System Server and Device Management
Deploy, manage, and remotely assist AWS servers and corporate devices across Windows, macOS, iOS, Linux, AWS Linux AMIs, and Android from a single cloud platform
Passwordless and Conditional Access
Enable phishing-resistant access with passwordless SSO, password management, and conditional access controls to ensure only specific users on trusted devices and networks can access AWS resources
Unified Platform with Zero Trust Capabilities
Combine cloud directory identity management, access management, and cross-OS server and device management with enhanced IAM and device management controls to support Zero Trust security goals
Single Sign-On (SSO)
Automatically synchronizes users across multiple directories to enable one-click access to corporate applications on-premises and in the cloud with enforced security policies and self-service password reset capabilities.
Multi-Factor Authentication (MFA)
Supports multiple authentication methods including passwordless authentication, passkeys, one-time passcodes, push notifications, biometric data, and security keys with real-time reporting and monitoring of authentication events.
Adaptive Authentication
Delivers multi-layer, context-aware and risk-based protection to minimize common attacks and enforce contextual access security policies based on user behavior and risk assessment.
Identity Lifecycle Management
Provides role-based user provisioning engine with granular access permissions, least-privileged access controls, and automated user account provisioning across applications and AWS services.
Directory Integration
Acts as a secure cloud-based directory with integration capabilities for Active Directory, LDAP, G Suite and other external directories, plus pre-built connectors with thousands of third-party web applications and AWS services including AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge.
Active directory donain controller 2016 with new security features
Reviewed on Aug 18, 2023
Review provided by G2
What do you like best about the product?
The best about active directory donain controller 2016 is the new feature of PAM or privileged identity management. A new forest which can be provisioned by MIM( Microsoft Identity Manager) provides some good identity security features. Time Bound group memberships can be used to set up just in time access. Also this version of active directory can be joined easily with azure AD .
What do you dislike about the product?
This 2016 version is really good and easy to backup or setup also . So I didn't find and point to dislike about it
What problems is the product solving and how is that benefiting you?
It's PAM features is helpful to protect organisation from identity theft also it's BYOD and MDM capabilities is useful. We can auto enroll devices to intune even other third party)
Bhavana G.
DNS Hierarchy & Directory Data Processing is good with AD DC 2016 Edition
Reviewed on Nov 28, 2021
Review provided by G2
What do you like best about the product?
Active Directory Domain Controller 2016 is capable of maintaining credible user account information and undertakes proper authentication & authorization process. It gives the ease to find user-specific information and organizes the directory with logical and hierarchical data stores. It provides a food reposition for AD objects, shared resources, and user account privileges.
What do you dislike about the product?
Since it offers centralized resource management and security administration, it isn't easy to handle when your organization works with distributed data stores. Authentication for global resources needs better standards for assurance of our enterprise hierarchy. It is pretty outdated and cannot be used in modern distributed platforms to meet up with our demands.
What problems is the product solving and how is that benefiting you?
Active Directory Domain Controller is applicable while having an organization model which requires logical division of user administration and service roles. It has capabilities to administer the AS remotely, thanks to its in-built modules. It's relatively easy to set up and instantiate new DNS with its group policies that accurately publish domain objects and securely allow users to access our network resources.