Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The following tables list the Amazon Web Services (AWS) and Google Cloud Platform (GCP) services and resource types supported by Microsoft Defender Cloud Security Posture Management (Defender CSPM) after you connect an AWS account or GCP project.
Not every Defender CSPM capability or security recommendation applies to every listed resource type. This list doesn't indicate vulnerability scanning, threat protection, or coverage by a Defender workload protection plan. It also doesn't identify the resources used to calculate Defender CSPM charges. For those resources, see Defender CSPM billable resources.
AWS resources
| Service | Resource type |
|---|---|
| AWS | Account Access key AWS Marketplace Web Service access key User cookie |
| AWS AppSync | GraphQL API |
| AWS Backup | Backup plan Backup vault |
| AWS Batch | Job definition Job queue |
| AWS Certificate Manager (ACM) | Certificate |
| AWS CloudFormation | StackSet Stack |
| AWS CloudTrail | Trail |
| AWS CodeArtifact | Domain Repository |
| AWS CodeBuild | Build project |
| AWS CodePipeline | Pipeline Webhook |
| AWS Config | AWS Config rule |
| AWS DataSync | Task |
| AWS Database Migration Service | Replication instance |
| AWS Glue | Job |
| AWS IAM Identity Center | Permission set |
| AWS Identity and Access Management (IAM) | IAM user group Customer managed policy IAM role IAM user |
| AWS Key Management Service (AWS KMS) | KMS key |
| AWS Lambda | Function |
| AWS Network Firewall | Firewall |
| AWS Step Functions | State machine |
| AWS WAF | Web ACL |
| Amazon API Gateway | Stage |
| Amazon AppFlow | Flow |
| Amazon AppStream 2.0 | Stack |
| Amazon Athena | Workgroup |
| Amazon Bedrock | Agent Custom model Knowledge base |
| Amazon CloudFront | Distribution |
| Amazon Cognito | Identity pool User pool |
| Amazon Comprehend | Entity recognizer |
| Amazon DocumentDB | DB cluster |
| Amazon DynamoDB | Table |
| Amazon DynamoDB Accelerator (DAX) | Cluster DAX cluster |
| Amazon EC2 | Flow log Transit gateway Virtual private gateway Amazon Machine Image (AMI) EC2 instance Network ACL Elastic network interface Route table Security group Amazon EBS snapshot Subnet Amazon EBS volume VPC |
| Amazon EC2 Auto Scaling | Auto Scaling group |
| Amazon ECR | Repository |
| Amazon ECS | Task definition Cluster Service Container Task |
| Amazon EFS | File system |
| Amazon EKS | Cluster |
| Amazon EMR | Cluster |
| Amazon ElastiCache | Serverless cache Cache cluster |
| Amazon EventBridge | Event bus Pipe Rule |
| Amazon FSx | Amazon FSx for Lustre file system Amazon FSx for OpenZFS file system Amazon FSx for Windows File Server file system File system |
| Amazon Kendra | Index |
| Amazon Keyspaces | Table |
| Amazon Kinesis Data Streams | Data stream |
| Amazon Lightsail | Bucket Block storage disk Database Instance |
| Amazon MQ | Broker |
| Amazon MSK | MSK cluster |
| Amazon MemoryDB | Cluster |
| Amazon Neptune | DB instance DB cluster |
| Amazon OpenSearch Service | OpenSearch Service domain OpenSearch Serverless collection |
| Amazon QuickSight | Amazon QuickSight |
| Amazon RDS | Database connection string DB instance DB cluster DB cluster snapshot Unclear/nonstandard RDS identifier DB snapshot |
| Amazon Redshift | Amazon Redshift credentials Cluster |
| Amazon Route 53 | Health check Hosted zone |
| Amazon S3 | Amazon S3 presigned URL Access Point Bucket |
| Amazon SNS | Topic |
| Amazon SQS | Queue |
| Amazon SageMaker AI | App Domain Endpoint Model |
| Amazon VPC | Security group |
| CodeCommit | Repository |
| Codepipeline | Pipeline |
| Elastic Load Balancing | Classic Load Balancer Application/Network/Gateway Load Balancer |
GCP resources
| Service | Resource type |
|---|---|
| AI custom model | Custom model |
| AlloyDB for PostgreSQL | Cluster Instance |
| App Engine | Application SSL certificate Service |
| Artifact Registry | Repository |
| BigQuery | Table Dataset |
| Certificate Manager | Certificate |
| Cloud DNS | Managed zone |
| Cloud Deploy | Delivery pipeline |
| Cloud Key Management Service | CryptoKey KeyRing |
| Cloud Load Balancing | Forwarding rule External or internal Application Load Balancer Backend service Target pool Target TCP proxy |
| Cloud Run | Service |
| Cloud SQL | Cloud SQL instance |
| Cloud Storage | Bucket |
| Compute Engine | Disk VPC firewall rule Image Managed instance group Instance group VM instance VPC network Project metadata Subnet |
| Container Registry | Container Registry repository |
| Dataflow | Job |
| Dataproc | Cluster |
| Datastream | Stream |
| Filestore | Instance |
| Firestore | Database |
| Google Cloud | API key Google Cloud source Service account key Convenience value Domain Group Service account Special group User Cloud Storage signed URL |
| Google Kubernetes Engine (GKE) | Cluster |
| Identity and Access Management (IAM) | IAM policy binding |
| Memorystore | Memcached instance Redis instance Redis Cluster |
| Network | Network interface |
| Pub/Sub | Subscription Topic |
| Resource Manager | Organization Project Folder |
| Secret Manager | Secret |
| Spanner | Database Instance |
| Vertex AI | Workbench instance Batch prediction endpoint Dataset Endpoint Vector Search index |
| Vertex AI Search | Data store Engine |
| Vertex AI Workbench | Workbench instance |