Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
03Microsoft Defender for Cloud6 modules · 48 units · 4 hr 17 min · Cloud security posture, multicloud onboarding, workload protection, alerts, and response0/48 units complete
Learning path 03 · Microsoft Defender for Cloud

6 modules · 48 units · 4 hr 17 min · Cloud security posture, multicloud onboarding, workload protection, alerts, and response

0%

Study focus

Cloud posture and coverage

Connect Azure and hybrid resources, extend multicloud coverage, and manage cloud security posture.

Workload threat response

Enable workload protections, investigate alerts, and remediate risks across cloud resources.

6 modules · 48 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Connect non-Azure resources to Microsoft Defender for Cloud

Focus: Azure Arc, non-Azure servers, AWS accounts, GCP projects, and multicloud permissions.
0/7
01 / 07Introduction

Defender for Cloud provides one security view across Azure, on-premises, AWS, and Google Cloud. Each connection method must establish inventory, permissions, and the monitoring components needed by selected plans.

Official moduleMulticloud objectives
02 / 07Protect non-Azure resources

Azure Arc projects servers and Kubernetes clusters from other clouds or on-premises into the Azure control plane. Arc enables Azure resource identity, policy, extensions, tagging, inventory, and supported Defender for Cloud protections.

Exam takeaway: Arc-enabled is more than security-agent onboarding; it makes the external machine an Azure-manageable resource.
Official lessonAzure Arc and hybrid protection
03 / 07Connect non-Azure machines

Onboard a machine to Azure Arc using an installation script, supported configuration tooling, or at scale through service-principal-based deployment. Then enable the required Defender plans and extensions. Direct MDE onboarding is an alternative for endpoint protection but lacks Arc's Azure management, policy, and extension features.

Official lessonHybrid server connection options
04 / 07Connect your AWS accounts

The AWS connector integrates AWS account inventory and AWS Security Hub findings. It can add secure-score recommendations, regulatory compliance, vulnerability assessment, MDE/EDR, and Arc-based server or Kubernetes capabilities according to enabled plans.

  1. Go to Environment settings and add an AWS environment.
  2. Select accounts or organization scope, regions, and scan interval (4, 6, 12, or 24 hours).
  3. Choose Defender plans and automatic provisioning options.
  4. Deploy the generated CloudFormation stack and grant required permissions.
  5. Verify connector health and recommendations.
Official lessonAWS connector configuration
05 / 07Connect your GCP accounts

The GCP connector imports project or organization resources and Security Command Center findings, then evaluates recommendations, secure score, and standards such as CIS.

  1. Enter organization or project details and select plans.
  2. Run the generated gcloud script to create workload identity, service accounts, and policy bindings.
  3. Enable required APIs: IAM, STS, Cloud Resource Manager, IAM Credentials, and Compute.
  4. Create and verify the connector; recommendations can take up to six hours to appear.
Official lessonGCP connector and permissions
06 / 07Module assessment

Review Arc versus direct MDE onboarding, AWS Security Hub versus GCP Security Command Center integration, generated deployment scripts, scan intervals, and required cloud permissions.

Official assessmentMulticloud connection knowledge check
07 / 07Summary and resources

Choose a connection model that supplies enough inventory, identity, telemetry, and control-plane access for the protections you intend to use, while granting least-privileged cloud permissions.

Official moduleSummary and resources
End of learning pathMicrosoft Defender for Cloud