AWS AmazonRDS: Reworded Self-Managed Active Directory setup clicks to choices
Summary
Mechanical copyedit across the RDS for SQL Server self-managed Active Directory setup guide replacing "Click"/"Right-click …" instructions with "Choose"/"Open the context (right-click) menu for …", plus similar Next/Save/Finish/Store wording updates. No procedural, permission, or cryptographic content is added or removed.
Security assessment
The only changed lines swap imperative UI verbs (for example "Right-click the domain…" becomes "Open the context (right-click) menu for the domain…"). Surrounding statements such as avoiding the AWS default KMS key, storing domain service account credentials in AWS Secrets Manager, and delegating limited rights remain untouched, so neither access-control nor encryption behavior described in the document actually changes. This yields no exploitable detail disclosure or misconfiguration fix worth rating above informational.
Evidence
3. Open the context (right-click) menu for the domain and choose **New** , then **Organizational Unit**.
Diff
diff --git a/AmazonRDS/latest/UserGuide/USER_SQLServer_SelfManagedActiveDirectory.SettingUp.md b/AmazonRDS/latest/UserGuide/USER_SQLServer_SelfManagedActiveDirectory.SettingUp.md index d2deb7554..4a8bfc082 100644 --- a//AmazonRDS/latest/UserGuide/USER_SQLServer_SelfManagedActiveDirectory.SettingUp.md +++ b//AmazonRDS/latest/UserGuide/USER_SQLServer_SelfManagedActiveDirectory.SettingUp.md @@ -40 +40 @@ We recommend creating a dedicated OU and service credential scoped to that OU fo - 3. Right-click the domain and choose **New** , then **Organizational Unit**. + 3. Open the context (right-click) menu for the domain and choose **New** , then **Organizational Unit**. @@ -46 +46 @@ We recommend creating a dedicated OU and service credential scoped to that OU fo - 6. Click **OK**. Your new OU will appear under your domain. + 6. Choose **OK**. Your new OU will appear under your domain. @@ -59 +59 @@ The domain service account credentials will be used for the secret in AWS Secret - 2. Right-click the **Users** object and choose **New** , then **User**. + 2. Open the context (right-click) menu for the **Users** object and choose **New** , then **User**. @@ -61 +61 @@ The domain service account credentials will be used for the secret in AWS Secret - 3. Enter a first name, last name, and logon name for the user. Click **Next**. + 3. Enter a first name, last name, and logon name for the user. Choose **Next**. @@ -63 +63 @@ The domain service account credentials will be used for the secret in AWS Secret - 4. Enter a password for the user. Don't select **"User must change password at next login"**. Don't select **"Account is disabled"**. Click **Next**. + 4. Enter a password for the user. Don't select **"User must change password at next login"**. Don't select **"Account is disabled"**. Choose **Next**. @@ -65 +65 @@ The domain service account credentials will be used for the secret in AWS Secret - 5. Click **OK**. Your new user will appear under your domain. + 5. Choose **OK**. Your new user will appear under your domain. @@ -76 +76 @@ The domain service account credentials will be used for the secret in AWS Secret - 2. Right-click the OU that you created earlier and choose **Delegate Control**. + 2. Open the context (right-click) menu for the OU that you created earlier and choose **Delegate Control**. @@ -78 +78 @@ The domain service account credentials will be used for the secret in AWS Secret - 3. On the **Delegation of Control Wizard** , click **Next**. + 3. On the **Delegation of Control Wizard** , choose **Next**. @@ -80 +80 @@ The domain service account credentials will be used for the secret in AWS Secret - 4. On the **Users or Groups** section, click **Add**. + 4. On the **Users or Groups** section, choose **Add**. @@ -82 +82 @@ The domain service account credentials will be used for the secret in AWS Secret - 5. On the **Select Users, Computers, or Groups** section, enter the AD domain service account you created and click **Check Names**. If your AD domain service account check is successful, click **OK**. + 5. On the **Select Users, Computers, or Groups** section, enter the AD domain service account you created and choose **Check Names**. If your AD domain service account check is successful, choose **OK**. @@ -84 +84 @@ The domain service account credentials will be used for the secret in AWS Secret - 6. On the **Users or Groups** section, confirm your AD domain service account was added and click **Next**. + 6. On the **Users or Groups** section, confirm your AD domain service account was added and choose **Next**. @@ -86 +86 @@ The domain service account credentials will be used for the secret in AWS Secret - 7. On the **Tasks to Delegate** section, choose **Create a custom task to delegate** and click **Next**. + 7. On the **Tasks to Delegate** section, choose **Create a custom task to delegate** and choose **Next**. @@ -96 +96 @@ The domain service account credentials will be used for the secret in AWS Secret - 4. Select **Delete selected objects in this folder** and click **Next**. + 4. Select **Delete selected objects in this folder** and choose **Next**. @@ -104 +104 @@ The domain service account credentials will be used for the secret in AWS Secret - 3. Select **Validated write to service principal name** and click **Next**. + 3. Select **Validated write to service principal name** and choose **Next**. @@ -108 +108 @@ The domain service account credentials will be used for the secret in AWS Secret - 10. For **Completing the Delegation of Control Wizard** , review and confirm your settings and click **Finish**. + 10. For **Completing the Delegation of Control Wizard** , review and confirm your settings and choose **Finish**. @@ -141 +141 @@ For **Encryption Key** , don't use the AWS default KMS key. Be sure to create th - 2. For **Regionality** , choose **Single-Region key** and click **Next**. + 2. For **Regionality** , choose **Single-Region key** and choose **Next**. @@ -147 +147 @@ For **Encryption Key** , don't use the AWS default KMS key. Be sure to create th - 7. (Optional) For **Tags** , provide a tag the KMS key and click **Next**. + 7. (Optional) For **Tags** , provide a tag the KMS key and choose **Next**. @@ -151 +151 @@ For **Encryption Key** , don't use the AWS default KMS key. Be sure to create th - 9. For **Key deletion** , keep the box selected for **Allow key administrators to delete this key** and click **Next**. + 9. For **Key deletion** , keep the box selected for **Allow key administrators to delete this key** and choose **Next**. @@ -153 +153 @@ For **Encryption Key** , don't use the AWS default KMS key. Be sure to create th - 10. For **Key users** , provide the same IAM user from the previous step and select it. Click **Next**. + 10. For **Key users** , provide the same IAM user from the previous step and select it. Choose **Next**. @@ -171 +171 @@ For **Encryption Key** , don't use the AWS default KMS key. Be sure to create th - 13. Click **Finish**. + 13. Choose **Finish**. @@ -198 +198 @@ Be sure to create the secret in the same AWS account that contains the RDS for S - 4. For **Encryption key** , enter the KMS key that you created in a previous step and click **Next**. + 4. For **Encryption key** , enter the KMS key that you created in a previous step and choose **Next**. @@ -204 +204 @@ Be sure to create the secret in the same AWS account that contains the RDS for S - 7. For **Resource permission** , click **Edit**. + 7. For **Resource permission** , choose **Edit**. @@ -246 +246 @@ JSON - 9. Click **Save** then click **Next**. + 9. Choose **Save** then choose **Next**. @@ -250 +250 @@ JSON - 11. Review the settings for the secret and click **Store**. + 11. Review the settings for the secret and choose **Store**.