AP Profiles
AP Profiles (Auto-Provision Profiles) are used to automatically provision and deprovision WorkSpaces for users based on their membership in security groups.
AP Profiles define how users authenticate and how applications are assigned within WorkSpaces Manager. Profiles can be linked either to traditional on-premises Active Directory groups or to Microsoft Entra ID groups.
There are two main profile categories:
Local Active Directory Groups
Microsoft Entra ID Groups (Cloud or Synced)
Local Active Directory Groups
Local Active Directory AP Profiles are designed for environments where users and groups are managed directly from an on-premises Active Directory domain.
These AP profiles allow administrators to:
Assign WorkSpaces Images/Bundles based on AD security groups
Select Encryption Keys for system and user volumes
Choose tags to be automatically assigned
Reuse current organizational units and permissions
Microsoft Entra ID Groups
Microsoft Entra ID AP Profiles are intended for cloud-based identity management scenarios. These profiles support both:
Native cloud-only Entra ID groups
Hybrid synchronized groups from Active Directory using Azure AD Connect / Entra Connect
This model enables centralized identity management across cloud and hybrid environments.
Configuration
You can enable Auto-Provisioning of WorkSpaces by adding users to an Active Directory group and configuring WorkSpaces Manager to read users from that group. To start, select Add Profile.

When Auto-Provision is enabled, the service will poll the Active Directory groups every 15 minutes for new members.
The following information is required to create and configure an Auto-Provision (AP) Profile:
Active – Specifies whether the AP Profile is active. If disabled the group will not be scanned for new users and no WorkSpaces will be provisioned.
Group Name – Specify the Active Directory or Entra ID group used for provisioning.
Account – Select the AWS account where the WorkSpaces will be created (if multiple accounts are configured).
Region – Select the AWS Region for the WorkSpaces.
Directory – Select the WorkSpaces directory (AWS Directory Services or AD Connector).
Bundle – Select the WorkSpaces bundle.
Running Mode – Select the desired running mode.
Tags – Select the profile tags to be automatically applied.
Encryption – Enable or disable root and user volume encryption. Keys are specified on the Directory.
Directories – Enable or Disable the use of multiple directories. When enabled, Auto-Provision selects the directory with the highest available IP capacity when creating a WorkSpace.
Termination – Enable or disable termination on group removal.
IdP Groups – Allows to use Entra ID Groups, but it requires to set up also Microsoft Graph Settings to access Entra ID in Azure. More information here.
Temporary Provisioning: Define how many days the WorkSpace remains active before automatic termination, and how many days prior to termination users are notified.
Removing a user from an AD group does not automatically terminate the WorkSpace by default. Termination on group removal will only occur if the Terminate on Group Removal option is enabled and the WorkSpace has the Automation - Managed tag applied.
You will only be allowed to add "Fixed Tags" in Profile Tags once you’ve saved the Auto-Provision profile. If you go back to edit this profile, you can then add the Fixed Tags.

WSM uses Directory Selection Behaviour, where when Use Multiple Directories is enabled, you can select one or more directories for provisioning. The service then evaluates the selected directories based on available IP capacity and chooses the most suitable option. If provisioning fails due to capacity constraints, it automatically retries using the next best directory, and all attempts are logged for audit and troubleshooting purposes.
Users can be assigned the read-only permission Permissions.Configuration.ApProfilesReadonly under Security > Roles in the configuration options. This allows them to view AP Profiles without being able to create, edit, or delete profiles.
Last updated

