WorkSpaces without configured encryption

Encrypt WorkSpaces user volumes at creation and plan migration of existing data.

Description

Amazon WorkSpaces provides virtual desktops that store user files, settings and business data. User-volume encryption protects stored data and snapshots of that volume. An unencrypted volume lacks this protection.

This feature protects cloud volumes; it does not prevent compromise of a user’s endpoint or account. Manage authentication and access permissions separately.

Potential impact

Unauthorized acquisition of stored volumes or snapshots can expose user documents and business data. It may also leave organizational encryption requirements unmet.

Remediation

  • Set UserVolumeEncryptionEnabled: true for new WorkSpaces and review root-volume encryption as well.
  • Use an AWS managed key or an appropriate symmetric customer managed KMS key, keeping required permissions and the key enabled.
  • An existing WorkSpace cannot be encrypted after creation. Preserve data and plan migration to a new encrypted WorkSpace. CloudFormation also does not support updating encryption properties alone.

Examples

These are creation excerpts. Define WSTypeMap, WorkstationType and UserName in the full template, supplying a valid bundle, directory and user.

Before

yaml
Resources:
  MyWorkSpace:
    Type: AWS::WorkSpaces::Workspace
    Properties:
      BundleId: !FindInMap
        - WSTypeMap
        - !Ref WorkstationType
        - BundleId
      DirectoryId: !FindInMap
        - WSTypeMap
        - !Ref WorkstationType
        - DirectoryId
      UserName: !Ref UserName

This does not explicitly request user-volume encryption. Check the deployed WorkSpace’s actual encryption state.

After

yaml
Resources:
  MyWorkSpace:
    Type: AWS::WorkSpaces::Workspace
    Properties:
      BundleId: !FindInMap
        - WSTypeMap
        - !Ref WorkstationType
        - BundleId
      DirectoryId: !FindInMap
        - WSTypeMap
        - !Ref WorkstationType
        - DirectoryId
      UserName: !Ref UserName
      UserVolumeEncryptionEnabled: true

This requests user-volume encryption for a new WorkSpace. Root-volume encryption is a separate setting, and this example does not migrate existing user data automatically.

References