AWS Security ChangesHomeSearch

AWS mgn: Added critical network isolation guidance for domain controllers

Service: mgn · 2026-08-31 · Documentation medium

File: mgn/latest/ug/preparing-environments.md · Type: network

Summary

Introduced warnings about isolating test VPCs from production networks to prevent unintended domain controller binding.

Security assessment

The addition provides security-adjacent best practices to prevent production network disruption through misconfiguration, emphasizing network segmentation risks.

Evidence

+Isolate your test VPC from your production network. If you launch a domain controller into a test VPC that has a network route back to your on-premises or production environment, production clients might bind to the launched domain controller instead of your production Active Directory, which can disrupt production workloads.

Diff

diff --git a/mgn/latest/ug/preparing-environments.md b/mgn/latest/ug/preparing-environments.md
index 8756e6944..67c431b25 100644
--- a//mgn/latest/ug/preparing-environments.md
+++ b//mgn/latest/ug/preparing-environments.md
@@ -81,0 +82,8 @@ For details on configuring DNS and network connectivity for domain-joined server
+###### Important
+
+Isolate your test VPC from your production network. If you launch a domain controller into a test VPC that has a network route back to your on-premises or production environment, production clients might bind to the launched domain controller instead of your production Active Directory, which can disrupt production workloads. When testing, we recommend that you do not launch Active Directory domain controllers into an environment that has connectivity to production, and that you remove any routes between your test VPC and your production network.
+
+Cutover is different. A cutover instance is intended to replace your production server, so connectivity to your existing environment is expected. When you cut over a domain controller, plan the timing carefully: coordinate the shutdown of the corresponding on-premises or source domain controller with the cutover so that clients transition to the migrated domain controller in a controlled way, rather than having two active domain controllers serve the same clients at once.
+
+If you plan to operate in a hybrid configuration, where your on-premises environment remains online alongside servers migrated to the cloud, plan network connectivity between the two environments carefully. Ensure that clients resolve and connect to the intended Active Directory domain controllers so that you avoid unexpected results, such as clients binding to the wrong domain controller.
+