Table of contents

Add Amazon WorkSpaces

Amazon WorkSpaces are virtual cloud desktops that run in Amazon Web Services (AWS). You can protect them with Workload Security.

The agent only supports Amazon WorkSpaces Windows desktops — it does not support Linux desktops.

After completing the required steps, your Amazon WorkSpaces:

  • Are displayed in the Workload Security console on the left under Computers > your_AWS_account > your_region > WorkSpaces.
  • Are protected by the agent.

Protect Amazon WorkSpaces if you already added your AWS account

If you already added your AWS account to Workload Security (to protect your Amazon EC2 instances), complete the following steps to configure Workload Security to work with Amazon WorkSpaces:

  1. Launch an Amazon WorkSpace, and then install and activate agent version 10.2 or later on it. See Install the agent on Amazon EC2 and WorkSpaces for details. Optionally, create a custom WorkSpace bundle so that you can deploy it to many people. See Bake the agent into your AMI or WorkSpace bundle for details on installation, activation, and bundle creation.
  2. Modify your IAM policy to include Amazon WorkSpaces permissions:

  3. Log in to AWS with the account that was added to Workload Security.

  4. Go to the IAM service.
  5. Find the Workload Security IAM policy. You can find it under Policies on the left, or you can look for the Workload Security IAM role or IAM user that references the policy and then click the policy within it.
  6. Modify the Workload Security IAM policy to look like the one shown in Add an AWS account using a cross-account role. The policy includes Amazon WorkSpaces permissions. If you added more than one AWS account to Workload Security, the IAM policy must be updated under all the AWS accounts.

  7. In the Workload Security console, edit your AWS account:

  8. On the left, right-click your AWS account and select Properties.

  9. Enable Include Amazon WorkSpaces.
  10. Click Save.

You have now added Amazon WorkSpaces to Workload Security.

Protect Amazon WorkSpaces if you have not yet added your AWS account

If you have not yet added your AWS account to Workload Security, complete one of the following: