Short for Amazon Web Services, Amazon's public cloud. Linking AWS accounts to Microsoft Defender for Cloud brings them under its recommendations and protections.
Also called Amazon Web Services.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-900DP-750SC-900SC-200AZ-802SC-401
Each book explains AWS in context, with comparison tables and the common traps.
Terms in this definition
- Public cloud
Services that a provider such as Microsoft owns, operates and sells to any customer. Nothing needs buying upfront, and charges follow actual consumption.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Microsoft Defender for Cloud
Combines security posture management with workload protection: a free foundational CSPM tier, paid Defender plans, Secure Score and recommendations. Its regulatory compliance dashboard shows status only and blocks nothing.
Related terms
- Amazon EC2
Amazon's virtual machine offering. Defender for Cloud can onboard EC2 instances automatically, installing Azure Arc and Defender components, when its AWS connector has Defender for Servers turned on.
- Amazon ECR
Amazon's registry service for container images, which Defender for Containers can scan once the AWS connector is in place.
- Amazon MSK
Amazon's managed Apache Kafka offering on AWS. In Fabric Real-Time Intelligence it can be added as an eventstream source to pull in its topics.
- AWS connector (Defender for Cloud)
Connector linking Defender for Cloud to Amazon Web Services, finished by running a generated CloudFormation template on the AWS side. If Defender for Servers is enabled, it provisions Azure Arc onto EC2 instances automatically.
- AWS IAM
Amazon's service for controlling who can sign in and what they may do across AWS. OneLake's Amazon S3 shortcuts depend on it: the cloud connection behind such a shortcut stores an IAM user's secret access key and its key ID.
- Cloud account
An endpoint plus credentials, for example for vCenter, NSX, VCF, AWS, Azure or Google Cloud, that VCF Operations and VCF Automation (VM Apps) use to gather data or provision resources.
- Microsoft Defender Experts for Servers
Microsoft analysts watching over your servers on your behalf, sold as an add-on service. It covers machines that have Defender for Servers Plan 1 or 2 enabled, wherever they run: Azure, AWS, GCP or your own data centre.
- Microsoft Defender for open-source relational databases
Detects threats like brute-force attempts against Azure Database for MySQL and PostgreSQL flexible servers, as well as Amazon RDS engines in linked AWS accounts; one of the Defender for Cloud plans.