Applying for the Workspace Service
Apply for the Workspace service. After you apply for Workspace, a secure and exclusive Workspace infrastructure will be deployed and a dedicated elastic IP address used for accessing Workspace will be allocated to you. The AD is a necessary component used for managing users and desktops. You can create an AD on the cloud or use an existing AD. After you apply for the Workspace service, you can purchase Workspace desktops.
When applying for Workspace, if the existing enterprise AD domain is used, refer to How Do I Interconnect Workspace with Microsoft AD? to enable related ports on the AD server and prepare the following data:
- Domain name
- Domain administrator's account and password
- Active domain controller IP address
- (Optional) Standby domain controller IP address
- Active DNS server IP address
- (Optional) Standby DNS server IP address
- Log in to the Workspace management console.
- On the Dashboard page, click Click here to complete real-name authentication and complete real-name authentication as prompted.
- On the Dashboard page, click Apply for Workspace.
The Apply for Workspace page is displayed.
- Select an AZ based on actual conditions.
An AZ is a physical region where resources use independent power supplies and networks. AZs are physically isolated but interconnected through an internal network, improving HA of applications.
- Click View VPC to create a VPC and a subnet.
For details about how to create a VPC, see the Virtual Private Cloud User Guide.NOTE:
You are advised to use 16-bit subnet gateways during VPC creation. After you apply for the Workspace service, do not modify the VPC configuration.
- Click to refresh the drop-down list.
- Configure the VPC.
Select the VPC and Service Subnet created in 5 and enter Management Subnet.NOTE:
- You can select multiple subnets to support more desktops.
- Use the subnet that is created in 5 and dedicated to Workspace. Do not use the subnet dedicated to other services.
- The service subnet is used by desktops to access applications and resources on ECSs or enterprises internets.
- The management subnet is used for internal communication among desktops.
- Configure the AD domain.
Check whether your enterprise has an AD domain.
- Create an AD domain.
Set the Domain Name, Domain Administrator Account, Domain Administrator Password, and Confirm Password parameters of the new AD domain.
After an AD domain is created, go to 11.NOTE:
To ensure system security, you need to change the password periodically. You are advised to change the password every three months.
- Connect to the existing domain.
Set the Domain, Domain Administrator Account, Domain Administrator Password, Primary domain controller IP address, Backup domain controller IP address (optional), Active DNS IP address, and Standby DNS IP address (optional) parameters of the existing domain.NOTE:
When you use an existing AD domain, ensure that the related ports of the firewall are enabled. For details, see How Do I Interconnect Workspace with Microsoft AD?.
- Specify the network access mode. By default, Internet access is selected. You can select multiple options.
If the network quality does not meet requirements, you can select DirectConnect access. For details about the network quality requirements, see What Are the Network Requirements for Accessing the Desktop?.NOTE:
The DirectConnect access mode provides the load balancing capability. Therefore, enterprises do not need to deploy third-party load balancers before access addresses.
- Read the Huawei Workspace Service Agreement.
- Select I have read and agree to the Huawei Workspace Service Agreement.
- Click Apply Now. The Workspace service application is complete.
- The application process takes about 40 minutes.
- The system creates WorkspaceManagerSecurityGroup and WorkspaceUserSecurityGroup security groups in the VPC during the application. WorkspaceManagerSecurityGroup is used for management components, and WorkspaceUserSecurityGroup is used for user desktops. By default, only virtual desktops in the WorkspaceUserSecurityGroup security group can access each other. If you want to access a virtual desktop in the security group from an external desktop, choose to modify the configurations.