Onboarding an AWS account to Microsoft Defender for Cloud starts in Defender for Cloud > Environment settings > Add environment > Amazon Web Services

Manage security posture by using Microsoft Defender for Cloud
Answer Correct answer: A — In Defender for Cloud, open Environment settings and add an Amazon Web Services environment to onboard the AWS account.

You have an Azure subscription that uses Microsoft Defender for Cloud. You have an Amazon Web Services (AWS) account. You need to add the AWS account to Defender for Cloud. What should you do first?

  1. From Defender for Cloud, configure the Environment settings. Correct Answer
  2. From the AWS account, enable a security hub.
  3. From Defender for Cloud, configure the Security solutions settings.
  4. From the Azure portal, add the AWS enterprise application.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Multi-cloud onboarding is a Defender for Cloud Environment settings action; you do not enable AWS Security Hub or register an enterprise app as the first step — the native connector is configured from Environment settings.

To connect an AWS account to Microsoft Defender for Cloud, you open Defender for Cloud in the Azure portal, go to Environment settings, and choose Add environment > Amazon Web Services. Environment settings is the single place to onboard multi-cloud (AWS/GCP) connectors and start monitoring.

Candidates pick 'enable a security hub' or 'add the AWS enterprise application', but the first step in Azure is Defender for Cloud > Environment settings, which creates the connector and required permissions.

Community Discussion (3 comments)

ITFranz 👍 1 Selected: A
To support the answer: https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws Connect your AWS account To connect your AWS to Defender for Cloud by using a native connector: Sign in to the Azure portal. Go to Defender for Cloud > Environment settings. Select Add environment > Amazon Web Services. Answer = A
obaemf 👍 2 Selected: A
Configure the Environment settings.
[Removed] 👍 3
Explanation: • Environment Settings in Defender for Cloud: This is where you manage the integration of external cloud environments such as AWS and GCP with Microsoft Defender for Cloud. By configuring the environment settings, you can onboard your AWS account, set up the necessary connectors, and establish monitoring and security management.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Defender for Cloud centralizes multi-cloud onboarding under Environment settings. You sign in to the Azure portal, go to Defender for Cloud > Environment settings, select Add environment > Amazon Web Services, and complete the native connector. (Option A)

Why the Other Options Are Wrong

  • Option B (Enable AWS Security Hub) is an AWS-side concern and not the Azure-first step for the Defender connector.
  • Option C (Security solutions settings) is a legacy blade not used for AWS onboarding.
  • Option D (Add the AWS enterprise application) is not how the native multi-cloud connector is established; Environment settings handles it.

Community Comment Notes

Comments confirmed A and cited the quickstart-onboard-aws article: 'Go to Defender for Cloud > Environment settings. Select Add environment > Amazon Web Services.'

Official Reference

Related Analysis

← Back to AZ-500 Study Guide