Connect hybrid and multicloud environments to Microsoft Defender for Cloud

Intermediate
Security Engineer
Microsoft Defender for Cloud
Azure

In this module, you connect on-premises servers, AWS accounts, and GCP projects to Microsoft Defender for Cloud to extend unified security coverage across your entire hybrid and multicloud estate. You learn how federated authentication secures connector access without storing long-lived credentials. Then you plan the right connector scope for each environment type, and configure native connectors for AWS and GCP. The module covers both CSPM (agentless) and CWPP (Azure Arc–enabled) coverage extension, and closes by verifying that unified posture and workload protection is active across all connected environments.

Learning objectives

After completing this module, you'll be able to:

  • Explain the multicloud connectivity model in Defender for Cloud, including how federated authentication works for AWS and GCP connectors
  • Plan a connector strategy for hybrid and multicloud environments, including scope, scan interval, and required permissions per environment type
  • Connect on-premises machines to Defender for Cloud using Azure Arc-enabled servers
  • Connect AWS accounts to Defender for Cloud using the native cloud connector and CloudFormation template
  • Connect GCP projects to Defender for Cloud using the native cloud connector and GCloud deployment script
  • Verify multicloud connectivity health and confirm CSPM and CWPP coverage surfaces across connected environments

Prerequisites

  • Familiarity with Microsoft Defender for Cloud at a basic level
  • Understanding of Azure resource types and Azure role-based access control (RBAC)
  • Knowledge of cloud IAM concepts including service accounts, roles, and trust relationships across Azure, AWS, and GCP

Get started with Azure

Choose the Azure account that's right for you. Pay as you go or try Azure free for up to 30 days. Sign up.