Onboarding an AWS account to Microsoft Defender for Cloud starts in Defender for Cloud > Environment settings > Add environment > Amazon Web Services
You have an Azure subscription that uses Microsoft Defender for Cloud. You have an Amazon Web Services (AWS) account. You need to add the AWS account to Defender for Cloud. What should you do first?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Multi-cloud onboarding is a Defender for Cloud Environment settings action; you do not enable AWS Security Hub or register an enterprise app as the first step — the native connector is configured from Environment settings.
To connect an AWS account to Microsoft Defender for Cloud, you open Defender for Cloud in the Azure portal, go to Environment settings, and choose Add environment > Amazon Web Services. Environment settings is the single place to onboard multi-cloud (AWS/GCP) connectors and start monitoring.
Candidates pick 'enable a security hub' or 'add the AWS enterprise application', but the first step in Azure is Defender for Cloud > Environment settings, which creates the connector and required permissions.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Defender for Cloud centralizes multi-cloud onboarding under Environment settings. You sign in to the Azure portal, go to Defender for Cloud > Environment settings, select Add environment > Amazon Web Services, and complete the native connector. (Option A)Why the Other Options Are Wrong
- Option B (Enable AWS Security Hub) is an AWS-side concern and not the Azure-first step for the Defender connector.
- Option C (Security solutions settings) is a legacy blade not used for AWS onboarding.
- Option D (Add the AWS enterprise application) is not how the native multi-cloud connector is established; Environment settings handles it.