Which solution will meet these requirements?
Use Amazon WorkSpaces for the cloud desktop service. Set up a VPN connection to the on-premises network. Create an AD Connector, and connect to the on-premises Active Directory. Activate MFA for Amazon WorkSpaces by using the AWS Management Console.
Use Amazon AppStream 2.0 as an application streaming service. Configure Desktop View for the employees. Set up a VPN connection to the on-premises network. Set up Active Directory Federation Services (AD FS) on premises. Connect the VPC network to AD FS through the VPN connection.
Use Amazon WorkSpaces for the cloud desktop service. Set up a VPN connection to the on-premises network. Create an AD Connector, and connect to the on-premises Active Directory. Configure a RADIUS server for MFA.
Use Amazon AppStream 2.0 as an application streaming service. Set up Active Directory Federation Services on premises. Configure MFA to grant users access on AppStream 2.0.
Explanations:
Amazon WorkSpaces with an AD Connector and MFA setup through the AWS Management Console does not support advanced MFA requirements, such as integrating with on-premises Active Directory for MFA. This option does not fully address the need for robust, enterprise-grade MFA and secure integration with on-prem AD.
Amazon AppStream 2.0 with AD FS and VPN could allow application streaming and integration with AD, but it would not provide the full desktop experience that users require. Also, AppStream does not natively replicate a complete desktop environment as required by the company.
Amazon WorkSpaces provides a full desktop experience, supports mixed OS environments, and can integrate directly with on-premises Active Directory through an AD Connector. By configuring a RADIUS server for MFA, this option meets all requirements: secure AD integration, MFA, and a similar user experience.
Amazon AppStream 2.0 with AD FS and MFA can provide access to applications, but it does not deliver the complete desktop experience required for the solution. AppStream is intended for application streaming, so it does not meet the requirement for a full desktop environment similar to what employees currently use.