Microsoft Defender for Cloud
Cloud and workloads

Enable data security posture management

In brief

The article now provides clearer prerequisites and setup guidance for enabling scanning of AWS S3 buckets and RDS instances, with updated links and next-step navigation.

What Defender admins need to know

Administrators configuring AWS resources can follow more specific requirements and scanning instructions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enable in Defender CSPM (AWS)

Follow these steps to enable data security posture management for your AWS resources. Review the prerequisites and then configure scanning for your S3 buckets and RDS instances.

Before you start in AWS

Complete the following checks before you enable data security posture management for Amazon Web Services (AWS):

  • Don't forget to: AWS discovery requirements for AWS discovery,, and required permissions for S3 and RDS scanning.
  • Check that there's no policy that blocks the connection to your Amazon S3 buckets.
  • For Amazon Relational Database Service (RDS) instances, cross-account AWS Key Management Service (KMS) encryption is supported, but additional KMS access policies might prevent access.

Enable for AWS resources

After you complete the prerequisites, configure scanning for your AWS resources.

Configure S3 buckets and RDS instances

To enable scanning for S3 buckets and RDS instances:

Check for S3 blocking policies

If the enable processenabling scanning for S3 buckets and RDS instances didn't work because of a blocked policy, check the following:

  • Make sure that the S3 bucket policy doesn't block the connection. In the AWS S3 bucket, select the Permissions tab > Bucket policy. Check the policy details to make sure the Microsoft Defender for Cloud scanner service running in the Microsoft account in AWS isn't blocked.
  • Make sure that there's no SCP policy that blocks the connection to the S3 bucket. For example, your SCP policy might block read API calls to the AWS Region where your S3 bucket is hosted.

Next steps

After you enable data security posture management, continue with the following step:

[!div class="nextstepaction"] Review security risks in your data