Defender for Cloud - AWS - Single Account Setup Errors

Chris T 0 Reputation points
2026-07-31T01:00:30.75+00:00

I am following the instructions to add an AWS account to Windows Defender for Cloud.

I have added the account using the web portal, downloaded the CloudFormation.template generated and successfully added the Stack to AWS. (it returns CREATE_COMPLETE, no errors on AWS)

I am using a Single Account (NOT a Management Account).

When Azure displays the environment, it shows an error "AWS SQS queue is missing credentials for Log collection extension."

I've waited the 3 hours for the error to clear, but does not and the connection does not appear to work! I'm further confused because the log collection extension shouldn't even be active because Defender CSPM is off.

Settings:

Foundational CSPM: On (free) Defender CSPM: Off Servers (Plan 2): On Databases: Off Containers: Off

Error message:

{
    "IssueName": "IssueWithDataSourceAccount",
    "WindowResult": "PermanentFailure",
    "StatusCode": "S3B40012",
    "StatusMessage": "Data fetch failed due to missing credentials for the SQS queue. Delete the existing AWS S3 data connector and connect a new one. If only the SQS queue was deleted, create a new Amazon SQS queue and configure the necessary SQS policy.",
    "HealthReportStatus": "NotHealthy"
}

There is no SQS queue created! So these instructions do not seem applicable. And from what I can tell, an SQS queue is only created when using a Management Account (I've looked at the CloudFormation.template and no where does it create a queue).

Why isn't this working?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

Answer accepted by question author

Konstantinos Lianos 505 Reputation points Student Ambassador
2026-07-31T07:35:48.6666667+00:00

Hello, @Chris T

The AWS deployment appears to have completed successfully, so the issue is most likely related to Defender for Cloud still provisioning or validating the connection.

Because this is a single AWS account and Defender CSPM is disabled, it should not need to create an SQS queue manually. The error may be caused by a temporary Azure-side synchronization issue or by a log collection setting enabled during onboarding.

It should wait a few more hours, refresh the environment status, and confirm that AWS CloudTrail log collection is not enabled.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Chris T 0 Reputation points
    2026-07-31T05:01:34.6766667+00:00

    It seems that after waiting a few hours, the environment is now connected.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.