Description
Amazon WorkSpaces provides virtual desktops that store user files, settings and business data. User-volume encryption protects stored data and snapshots of that volume. An unencrypted volume lacks this protection.
This feature protects cloud volumes; it does not prevent compromise of a user’s endpoint or account. Manage authentication and access permissions separately.
Potential impact
Unauthorized acquisition of stored volumes or snapshots can expose user documents and business data. It may also leave organizational encryption requirements unmet.
Remediation
- Set
UserVolumeEncryptionEnabled: truefor new WorkSpaces and review root-volume encryption as well. - Use an AWS managed key or an appropriate symmetric customer managed KMS key, keeping required permissions and the key enabled.
- An existing WorkSpace cannot be encrypted after creation. Preserve data and plan migration to a new encrypted WorkSpace. CloudFormation also does not support updating encryption properties alone.
Examples
These are creation excerpts. Define WSTypeMap, WorkstationType and UserName in the full template, supplying a valid bundle, directory and user.
Before
Resources:
MyWorkSpace:
Type: AWS::WorkSpaces::Workspace
Properties:
BundleId: !FindInMap
- WSTypeMap
- !Ref WorkstationType
- BundleId
DirectoryId: !FindInMap
- WSTypeMap
- !Ref WorkstationType
- DirectoryId
UserName: !Ref UserName
This does not explicitly request user-volume encryption. Check the deployed WorkSpace’s actual encryption state.
After
Resources:
MyWorkSpace:
Type: AWS::WorkSpaces::Workspace
Properties:
BundleId: !FindInMap
- WSTypeMap
- !Ref WorkstationType
- BundleId
DirectoryId: !FindInMap
- WSTypeMap
- !Ref WorkstationType
- DirectoryId
UserName: !Ref UserName
UserVolumeEncryptionEnabled: true
This requests user-volume encryption for a new WorkSpace. Root-volume encryption is a separate setting, and this example does not migrate existing user data automatically.