AWS Security Hub now scans Azure: a 2026 multicloud CSPM setup and buy-vs-build guide

AWS Security Hub now scans Azure VMs, containers, Function Apps and identities at AWS-equivalent prices. Setup, cost and buy-vs-build.

Read time
11 min
Word count
1.5K
Sections
10
FAQs
8
Share
Two cloud shapes joined by a light bridge, representing AWS and Azure security posture in one view
AWS Security Hub now scans Microsoft Azure resources next to AWS findings.
On this page · 10 sections
  1. What AWS shipped on July 14, 2026
  2. What Security Hub checks on Azure
  3. What it costs
  4. Security Hub multicloud versus Defender for Cloud versus a dedicated CSPM
  5. A setup checklist
  6. When to run it yourself versus use a managed team
  7. India-specific considerations
  8. FAQ
  9. How eCorpIT can help
  10. References

Summary. On July 14, 2026 AWS extended Security Hub to Microsoft Azure. It now discovers Azure Virtual Machines, container images, Function Apps, and identities, then checks them for misconfigurations, internet exposure, and software vulnerabilities, with posture checks against the CIS Microsoft Azure Foundations Benchmark. Azure findings sit next to AWS findings in the same finding format, with the same automation and response workflows, so one team works from one prioritized view. AWS prices Azure resources at the same rates as the equivalent AWS resources with no additional fees, and there is an independent 30-day free trial. Security Hub Essentials lists at $3.75 per resource unit in us-east-1, where an EC2 instance counts as 1 unit, a Lambda function 1/12, a container image 1/18, and an IAM user or role 1/125. A mid-sized Azure estate can land near $1,140 a month on that model, and the optional Threat Analytics add-on meters separately at $0.55 per GB. This guide covers what the Azure support actually checks, what a realistic monthly bill looks like, how it compares to Microsoft Defender for Cloud and Wiz, and when to run it in-house versus hand it to a managed team.

What AWS shipped on July 14, 2026

Cloud security posture management, or CSPM, is the practice of continuously checking cloud resources for risky configuration, exposure, and known vulnerabilities. Most teams have run CSPM per cloud, in separate consoles with separate rules. The Security Hub update collapses part of that split. Michael Fuller, who has led product for AWS Security Services for 11 years, wrote in the AWS announcement that customers "have been clear with us that they want Security Hub to also cover the rest of their estate," starting with Azure and "more clouds following quickly."

The mechanism matters for accuracy. Rather than the fixed polling interval many third-party tools use, AWS built the Azure evaluation on AWS Config, which now reads across clouds and re-evaluates a resource when it changes. That gives near-real-time posture rather than a once-a-day snapshot, which is the difference between catching an exposed database in minutes and catching it tomorrow.

The Azure support arrived alongside a broader push into AI-workload security in the same announcement: GuardDuty AI Protection went generally available, GuardDuty AI-powered investigations entered preview in 10 AWS Regions, and a new Security Hub AI inventory shipped inside the Essentials plan at no extra cost. The through-line is one prioritized view instead of another dashboard to staff.

What Security Hub checks on Azure

The Azure coverage is scoped to four resource types today, with benchmark posture on top.

Azure resource What Security Hub evaluates AWS-equivalent billing unit
Virtual Machines Misconfiguration, internet exposure, software vulnerabilities Like an EC2 instance (1 unit)
Container images Known software vulnerabilities in images Like an ECR image (1/18 unit)
Function Apps Misconfiguration and exposure Like a Lambda function (1/12 unit)
Identities Posture and access risk Like an IAM user or role (1/125 unit)
All of the above CIS Microsoft Azure Foundations Benchmark posture checks Priced same as equivalent AWS resources

Two limits are worth flagging before you plan a rollout. First, the coverage is those four resource types plus benchmark checks, not yet every Azure service, so it complements rather than replaces a full Azure-native tool for teams that live in Azure. Second, per AWS documentation, you cannot include a multicloud standard such as the CIS Azure Foundations Benchmark inside a Security Hub configuration policy. To enable or configure the multicloud standard you use local configuration directly in the AWS account, which changes how you script a large multi-account rollout.

What it costs

Security Hub Essentials is priced per resource unit, listed at $3.75 in us-east-1, and AWS bills Azure resources at the same rates as the equivalent AWS resources. Because the unit weights differ by resource type, the bill depends on your mix, not just your headcount of machines.

Take an Azure estate of 200 Virtual Machines, 600 Function Apps, 900 container images, and 500 identities. Mapped to the equivalent units, that is roughly 200 units for the VMs, about 50 units for the Function Apps at 1/12 each, about 50 units for the images at 1/18 each, and 4 units for the identities at 1/125 each. That totals near 304 units, or about $1,140 a month at $3.75 per unit, before the 30-day free trial. Confirm the exact Azure-to-AWS unit mapping against the Security Hub pricing page for your regions, because rates vary by region and the resource weights drive the number.

If you also turn on the optional Threat Analytics add-on for GuardDuty-powered detection, that meters separately, listed at $0.55 per GB for the first tier of security log volume. Keep it out of the base CSPM estimate and size it against your log volume.

Security Hub multicloud versus Defender for Cloud versus a dedicated CSPM

Security Hub joining the multicloud field does not end the CSPM decision. It changes it for teams whose center of gravity is already AWS. The three realistic options compare like this.

Vector AWS Security Hub multicloud Microsoft Defender for Cloud Dedicated CSPM (for example Wiz)
Home console AWS Security Hub Azure portal Vendor console
Azure coverage VMs, containers, Function Apps, identities; CIS Azure benchmark Deep, Azure-native Agentless, broad multicloud
AWS coverage Native Via Defender for Servers with the Arc agent Agentless
Evaluation cadence Near-real-time via AWS Config Continuous Often API polling
Attack-path analysis Finding correlation and exposure findings Azure-centric Security Graph, a market benchmark
Pricing model Per resource unit; Azure same as AWS Free CSPM tier plus paid plans Enterprise contract
Best fit AWS-centric teams adding Azure Microsoft-aligned teams Multicloud-first security teams

Read it as a center-of-gravity choice. Microsoft Defender for Cloud leads on native Azure integration, a free CSPM tier, and first-party ties to Entra ID and Azure Policy, which suits Microsoft-aligned shops. Wiz leads on agentless multicloud breadth and graph-based attack-path analysis, which suits security teams that treat every cloud as equal. Security Hub multicloud is the pragmatic pick when AWS is already your primary console and Azure is the smaller, secondary estate you want folded into the same triage queue rather than watched in a separate window. For teams weighing broader multicloud plumbing, our guide to AWS Systems Manager for Azure VMs covers the operations side of the same estate.

A setup checklist

The rollout is short but has an ordering that saves rework.

Enable Security Hub in your primary AWS security account and confirm the Essentials plan is active. Start the Azure connection during the 30-day free trial so you can size real spend before you pay. Onboard the Azure subscriptions you want covered, then configure the CIS Microsoft Azure Foundations Benchmark using local configuration in the AWS account, since it cannot go in a configuration policy. Point Azure and AWS findings at the same automation rules so a critical exposure raises the same ticket regardless of which cloud it came from. Then tune: suppress the benchmark rules that do not apply to your architecture before the noise trains your team to ignore the queue.

The honest failure mode of any CSPM is not missing a finding, it is drowning real findings in ones nobody triaged.

When to run it yourself versus use a managed team

CSPM earns its keep only if someone acts on the findings. That is the real buy-versus-build line, not the tool.

Factor Run Security Hub yourself Managed by a partner
Time to first findings Hours to enable, inside the 30-day trial Days, with initial tuning included
Ongoing triage Your team suppresses noise and chases owners Handled and reported
Azure onboarding You wire the connection and local config Done for you
Cost control You track resource-unit spend yourself Tracked and optimized
Data control Fully in your AWS account In your account, partner-operated
Best fit Teams with a dedicated cloud-security engineer Teams without in-house cloud security

A team with a security engineer who owns the queue should run it in-house; the tooling is now cheap enough and native enough that a separate product is hard to justify for a secondary Azure estate. A team without that person will collect findings and act on none of them, which is worse than no tool because it manufactures false comfort. If you are already rationalizing multicloud spend, the same discipline applies to cost as to security; see our multicloud FinOps guide for AWS, Azure and GCP and the broader cloud FinOps playbook for Indian teams. For securing the AI workloads that Security Hub's new AI inventory now surfaces, our GKE AI security blueprint covers the production-agent side.

India-specific considerations

For Indian teams the pricing lands in dollars, so the weak rupee matters. As of late July 2026 the US dollar traded around 96 rupees, so the roughly $1,140 example works out to about 1,09,000 rupees a month for that estate, before the free trial and before any Threat Analytics add-on. Budget in rupees and size the resource-unit count against your real Azure inventory, because the unit weights, not the machine count, drive the figure.

There is a compliance angle too. The Digital Personal Data Protection Act 2023 expects reasonable security safeguards over personal data, and misconfigured, internet-exposed cloud resources are a common route to a reportable breach. A single prioritized view of AWS and Azure exposure makes it easier to show that safeguards are monitored across the estate rather than per cloud. eCorpIT designs cloud data flows aligned with DPDP requirements; unified posture monitoring is one control that supports that alignment without claiming any certification the tool itself provides.

FAQ

How eCorpIT can help

eCorpIT helps AWS-centric teams fold their Azure estate into one Security Hub view, then actually work the queue. We enable multicloud posture during the free-trial window, wire the CIS Azure benchmark through local configuration, connect Azure and AWS findings to shared automation, and tune out the noise so criticals surface. That sits inside our cloud and FinOps managed service, where security posture and cloud spend are managed together. To scope a multicloud posture rollout, contact eCorpIT.

References

  1. AWS Security Blog, Michael Fuller, "Security Hub adds AI workload protection and multicloud support for Microsoft Azure," July 14, 2026: aws.amazon.com/blogs/security
  1. AWS, "AWS Security Hub supports monitoring Microsoft Azure" (What's New): aws.amazon.com/about-aws/whats-new
  1. AWS Security Hub, "Pricing": aws.amazon.com/security-hub/pricing
  1. AWS Security Hub, "Creating and associating configuration policies" (docs): docs.aws.amazon.com/securityhub
  1. Help Net Security, "AWS retools Security Hub for AI and multicloud threats," July 15, 2026: helpnetsecurity.com
  1. The New Stack, "AWS will now watch Microsoft's cloud for you": thenewstack.io/aws-security-hub-azure
  1. SiliconANGLE, "AWS turns Security Hub into an AI and multicloud security control plane," July 22, 2026: siliconangle.com
  1. Arnav, "Wiz vs Microsoft Defender for Cloud," June 27, 2026: arnav.au
  1. Protego, "Best CSPM Tools 2026: Defender for Cloud vs Wiz vs Orca vs Prisma Cloud": protego.me
  1. Exchange Rates UK, "US Dollar to Indian Rupee spot exchange rates history 2026": exchangerates.org.uk

_Last updated: July 29, 2026._

Frequently asked

Quick answers.

01 What does AWS Security Hub now cover on Microsoft Azure?
Security Hub discovers Azure Virtual Machines, container images, Function Apps, and identities, then evaluates them for misconfigurations, internet exposure, and software vulnerabilities. It adds posture checks against the CIS Microsoft Azure Foundations Benchmark. Azure findings appear next to AWS findings using the same finding format, automation, and response workflows in the same console.
02 How much does Security Hub multicloud cost for Azure?
AWS prices Azure resources at the same rates as equivalent AWS resources, with no additional fees and a 30-day free trial. Security Hub Essentials lists at $3.75 per resource unit in us-east-1, where an EC2 instance is 1 unit, a Lambda function 1/12, a container image 1/18, and an IAM user or role 1/125. Rates vary by region.
03 When did AWS Security Hub add Azure support?
AWS announced Security Hub multicloud support for Microsoft Azure on July 14, 2026, in a post by Michael Fuller on the AWS Security Blog. The same announcement introduced GuardDuty AI Protection at general availability, GuardDuty AI-powered investigations in preview across 10 AWS Regions, and a Security Hub AI inventory in the Essentials plan.
04 How is Security Hub multicloud different from a third-party CSPM?
Security Hub keeps findings in the AWS console and prices Azure resources like AWS ones, which suits AWS-centric teams. Dedicated tools such as Wiz lead on agentless multicloud breadth and graph-based attack-path analysis, and Microsoft Defender for Cloud leads on native Azure depth and a free CSPM tier. The best pick follows your primary cloud.
05 What is the CIS Microsoft Azure Foundations Benchmark check?
It is a set of configuration best practices for Azure published by the Center for Internet Security. Security Hub now evaluates covered Azure resources against that benchmark and reports failures as findings. Note that this multicloud standard cannot be included in a Security Hub configuration policy; you configure it using local configuration directly in the AWS account.
06 Does Security Hub scan AI workloads too?
Yes. The same July 2026 update added a Security Hub AI inventory that catalogs AI assets across Bedrock, SageMaker, and AgentCore, plus self-hosted models on EC2, ECS, and EKS. GuardDuty AI Protection detects anomalous model invocations, credential-driven cost harvesting, and prompt injection. The AI inventory is included in the Essentials plan at no additional cost.
07 Can I put the CIS Azure benchmark in a configuration policy?
No. Per AWS documentation, a multicloud standard such as the CIS Microsoft Azure Foundations Benchmark cannot be included in a Security Hub configuration policy. To enable or configure it, you use local configuration mechanisms directly in the desired AWS account. Plan large multi-account rollouts around that constraint rather than a central policy.
08 Should I run Security Hub myself or use a managed service?
Run it yourself if you have a security engineer who owns the findings queue; the tool is cheap and native enough to make a separate product hard to justify for a secondary Azure estate. Use a managed team if no one in-house will triage findings, because unactioned alerts create false comfort rather than real coverage.

About the author

Manu Shukla

Founder & Director

Founder of eCorpIT. Hands-on engineer leading senior-only delivery for AI apps, custom software, and cloud systems for global clients.

Subscribe

One engineering note a week. No fluff, no spam.

Senior-architect playbooks on AI agents, mobile apps, cloud, security, data, and marketing — delivered every Wednesday.

Past the reading

Read enough. Let's build something.

A senior architect responds in 24 working hours with scope, indicative cost, and a timeline. NDA before any technical conversation.