Microsoft Defender for Cloud
Identity protection

Integrate AWS CloudTrail logs

In brief

The page title now identifies Microsoft Defender for Cloud, and the CloudTrail warning clarifies that disabling ingestion removes data from the one-time historical collection while re-enabling it starts a new collection. The next-step heading and anchor were also updated.

What Defender admins need to know

Administrators should use the clarified wording when managing CloudTrail ingestion. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate AWS CloudTrail logs with Microsoft Defender for Cloud (Preview)

Microsoft Defender for Cloud can collect AWS CloudTrail management events to increase visibility into identity operations, permission changes, and other control-plane activity across your AWS environments.

- Select **Create a new AWS CloudTrail** to provision a new trail.
    1. Deploy the CloudFormation or Terraform template provided by Defender for Cloud when prompted.

Signals may take time to appear depending on CloudTrail delivery frequency and event volume.

Next steps

[!div class="nextstepaction"] Connect a Sentinel connected AWS account to Defender for Cloud