AWS just took a step many security teams had been asking for: AWS Security Hub now monitors Microsoft Azure resources, not only AWS. In the same wave of announcements, AWS added purpose-built protection for artificial intelligence workloads. For a CIO or CISO operating in more than one cloud —a common reality in Latin America— the change is concrete: fewer consoles, a single prioritized view of risk, and a more consistent response.
This analysis summarizes what AWS announced, verified against its official sources, and offers criteria for deciding when it makes sense to consolidate your multicloud security.
What AWS announced, in brief
AWS shared on July 7, 2026 that Security Hub begins monitoring Azure, and on July 14 it expanded the story with a focus on protecting AI workloads. These are two parallel moves pointing at the same idea: that your best security tools should work together instead of piling up isolated dashboards.
1. Multicloud security for Microsoft Azure
Security Hub now automatically discovers Azure resources —virtual machines, Azure Container Registry (ACR) container images, Function Apps and identities— and evaluates them for misconfigurations, internet exposure and software vulnerabilities. It applies posture checks against the CIS Microsoft Azure Foundations Benchmark and presents Azure findings prioritized next to AWS findings, using the same finding format and the same automation and response workflows you already use.
Commercially, AWS states that Azure resources are priced at the same rate as equivalent AWS resources, with no additional fees, and an independent 30-day free trial. The integration is available in most regions where Security Hub operates, and AWS said more clouds are coming soon.
2. Protection for artificial intelligence workloads
In parallel, AWS introduced three capabilities to close the visibility gap that AI workloads leave in production:
- Amazon GuardDuty AI Protection (available): threat detection built for Amazon Bedrock and Amazon SageMaker. It detects anomalous model invocations, cost harvesting attacks —where stolen credentials are used to run inference at your expense— and prompt injection attempts through the integration with Bedrock Guardrails. It analyzes CloudTrail data events and includes a 30-day free trial.
- GuardDuty AI-powered investigations (preview): automatically analyzes findings and the accounts around them, reviews up to 90 days of related activity, and returns a disposition with a confidence score, MITRE ATT&CK classification and recommendations. Available in preview in ten AWS Regions.
- AI inventory in Security Hub (available): a continuous, organization-wide view of your AI assets. It inventories managed resources across Bedrock, SageMaker and AgentCore, and discovers self-hosted models on Amazon EC2, ECS and EKS through runtime analysis, correlating them with GuardDuty findings. It is included in the Security Hub Essentials plan at no additional cost.
A summary of what is new
| Capability | What it solves | Status |
|---|---|---|
| Azure monitoring in Security Hub | Unified AWS and Azure posture in one console, with CIS Azure checks | Available |
| GuardDuty AI Protection | Detects anomalous invocations, cost harvesting and prompt injection in Bedrock and SageMaker | Available |
| GuardDuty AI-powered investigations | Automatic triage of findings with MITRE ATT&CK classification and confidence score | Preview |
| AI inventory in Security Hub | Discovers models, agents and pipelines across the organization | Available |
Why this matters for a company in Latin America
Most mid-size and large companies in the region do not live in a single cloud. AWS workloads coexist with Azure services —often inherited from Microsoft 365, from acquisitions, or from decisions made by different teams. That multicloud scenario carried a silent cost: two security tools, two consoles, two ways to prioritize, and teams jumping between them to understand a single risk.
Having Security Hub incorporate Azure reduces that cost. It does not eliminate the complexity of running multicloud, but it unifies the place where you prioritize and respond. For a small security team —the norm in the region— a single prioritized view of risk, with the same finding format and the same automation, frees up time that used to go into manual correlation.
The generative AI blind spot
One detail of the announcement is worth underlining, because it describes a risk that is already happening. AWS recounts a team that discovered a compromised service account —one that had been invoking a foundation model thousands of times— because the finance department questioned the bill. They found a security incident through an accounting review.
That is exactly the blind spot AI workloads introduce: models reach production faster than most security programs can keep up, and often there is no way to know which models, agents or endpoints exist across the organization. Cost harvesting converts stolen credentials into real spend without deploying anything. A continuous AI inventory and detection of anomalous invocations target precisely that gap.
When it makes sense to consolidate your multicloud security
The availability of a capability is not, on its own, a reason to adopt it. Some practical criteria:
- Consolidating makes more sense if you run production workloads in AWS and Azure at the same time, your security team is small and today loses time correlating findings across consoles, or if you need unified posture evidence for PCI-DSS or ISO 27001 audits.
- It can wait if your Azure presence is marginal or experimental, or if you already have a mature, standardized CSPM platform that covers both clouds well.
- In any case, if you are building with generative AI on AWS, the AI inventory and GuardDuty AI Protection close a blind spot worth addressing soon, whether you use one cloud or several.
The right decision depends on your cloud mix, the maturity of your processes and your regulatory obligations. It is not a box to check by default.
How we approach it at Caleidos
At Caleidos we design and implement cloud-native security on AWS: automatic controls in the pipeline (DevSecOps), posture management (CSPM), identity, encryption and monitoring, aligned to PCI-DSS, ISO 27001 and the local regulations of each country where you operate. Facing an announcement like this, our approach is measured: we assess whether consolidating your AWS and Azure posture in Security Hub adds real value to your case —or whether your priority lies elsewhere in the program— before recommending any change.
If you want to understand what this means for your architecture, let’s talk about your cloud security strategy.
Frequently asked questions
What did AWS announce about Security Hub and Azure? That Security Hub now monitors Microsoft Azure resources in addition to AWS: it discovers virtual machines, ACR container images, Function Apps and identities, and evaluates them against the CIS Microsoft Azure Foundations Benchmark, showing findings prioritized next to AWS findings.
How much does it cost to monitor Azure from Security Hub? According to AWS, Azure resources are priced at the same rate as equivalent AWS resources, with no additional fees, and a 30-day free trial when you create the integration.
Do I need to replace my Azure security tools? Not necessarily. Security Hub adds a unified posture and prioritization layer; it does not replace native Azure controls or your EDR or SIEM. Whether to consolidate depends on your cloud mix and the maturity of your processes.
Is this useful if my company only uses AWS? Yes. AWS added purpose-built protection for AI workloads —GuardDuty AI Protection for Bedrock and SageMaker, and an AI inventory in Security Hub— that closes a visibility blind spot even if you use a single cloud.