Overview
The CIS Hardened Image Level 1 on Microsoft Windows Server 2019 is a pre-configured image built by the Center for Internet Security (CIS®) for use on Amazon Elastic Compute Cloud (Amazon EC2). It is a pre-configured, security-hardened image that aligns with the robust security recommendations, the CIS Benchmarks, making it easier for organizations to meet regulatory requirements.
Not only is this image pre-hardened to the CIS Benchmarks guidance, but it is also patched monthly in alignment with the updates from the software vendor.
Key Benefits
This image is hardened against the corresponding Level 1 profile which is intended to be practical and prudent, provide a clear security benefit, and not inhibit the utility of the technology beyond acceptable means. No components are installed on or removed from this image outside of those already present on the base image or as recommended in alignment with the corresponding CIS Benchmark recommendations.
To demonstrate conformance to the CIS Microsoft Windows Server 2019 Level 1 Benchmark, industry-recognized hardening guidance, each image includes an HTML report from CIS Configuration Assessment Tool (CIS-CAT® Pro). Each CIS Hardened Image contains the following files:
These reports are located in C:\CIS Hardening Reports.
If this instance is used in a domain environment where policies are managed globally, the majority of the security settings will be changed and managed by domain policies.
For customized pricing options or private offers, reach out to us at cloudsecurity@cisecurity.org .
To learn more or access the corresponding CIS Benchmark, please visit https://www.cisecurity.org/cis-benchmarks or sign up for a free account on our community platform, CIS WorkBench, https://workbench.cisecurity.org/ .
Highlights
- Hardened according to a Level 1 CIS Benchmark that is developed in a consensus-based process and that is accepted by government, business, industry, and academia.
- Helps with compliance to PCI DSS, FedRAMP, DoD Cloud Computing SRG, FISMA, select NIST publications, and more.
- Pre-configured to align with industry best practices that are developed and supported by CIS, this image has hardened account and local policies, firewall configuration, and computer-based and user-based administrative templates.
Details
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
- ...
Dimension | Cost/hour |
|---|---|
t2.large Recommended | $0.022 |
t2.micro | $0.02 |
t3.micro | $0.022 |
r3.xlarge | $0.024 |
r5.24xlarge | $0.06 |
p3.8xlarge | $0.05 |
m6i.32xlarge | $0.06 |
x2iedn.32xlarge | $0.06 |
p5.48xlarge | $0.06 |
r5.8xlarge | $0.05 |
Vendor refund policy
Refunds through AWS are not available at this time. You will only be billed for actual time of instance use. As with all CIS security products, our aim is always 100 percent customer/member satisfaction.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
NA
Additional details
Usage instructions
Once the instance is running, choose Get Windows Password in the EC2 console then connect using a Remote Desktop Connection (RDP) client. The RDP client MUST be able to authenticate using NTLMv2. Immediately apply latest security updates after launching the instance.
Resources
Vendor resources
Support
Vendor support
Questions, feedback, and support accessing CIS-developed AMIs is provided by contacting
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Has consistently performed well and now requires better firmware updates and user interface improvements
What is our primary use case?
I integrated Windows Server in my infrastructure.
We use Hyper-V technology extensively, as it is very important for us, and it functions quite well.
What is most valuable?
Windows Server does what we need it to do, and security settings can be configured appropriately.
Hyper-V has affected our resource utilization and hardware costs, and we use it extensively.
What needs improvement?
The user interface of Windows Server needs improvement, especially when working with users, user accounts, and groups. There are multiple ways to accomplish tasks that do not align completely, so they need to rationalize their user interface for improvements in the future.
For how long have I used the solution?
I have been using Windows Server for 10 years.
What do I think about the stability of the solution?
We have experienced problems when upgrading the firmware on this unit, which has not been as smooth as it could be. It is difficult to compare since it is an old unit. The performance we see has not been exactly what was advertised.
How are customer service and support?
I have not used their technical support much at all, and it is usually difficult to reach the right personnel.
The first level support is not adequate and requires significant time.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I am looking for something else because I am not satisfied with my current solution.
I am generally satisfied, but now it is getting outdated and not suitable anymore, though it is an old model.
What's my experience with pricing, setup cost, and licensing?
The pricing for the Data Center version of Windows Server is not unreasonably priced. While it is not cheap, the cost is reasonable.
Which other solutions did I evaluate?
I am looking for a new solution for a NAS .
I do not have experience with Dell PowerStore or TrueNAS X-Series . I have limited experience with an old Synology. I am currently considering TrueNAS and Dell PowerScale . Pure Storage might be considered but will likely not be selected.
What other advice do I have?
I am not dealing with any Dell products in my system.
I have not worked with any all-flash storage arrays before, only with Synology.
My experience with Windows Server is fairly nice.
We will stay with Microsoft solutions.
I have been working with Microsoft, specifically with Windows Server and others, more on the programming side than on the system admin side, for 20 to 30 years. Windows Server is one of the two best options in the market. Either Linux or Windows Server is used, but if your software uses Windows, there are no alternatives.
I have faced some problems with Windows Server over many years of use, but they are typically solvable.
We have been a customer and partner of Microsoft, as we have been part of the Microsoft Partner Program.
I have not used Windows containers and Kubernetes for deploying cloud-native applications.
I would rate Windows Server 8 out of 10.
User interface provides friendly and comprehensive management experience
What is our primary use case?
At the office, the main use case for Windows Server involves different functions, for example, file server or firewall and the IIS server, Microsoft Internet Server, Internet Information Services. Basically, we use it as a file server for other applications on the server.
What is most valuable?
The best features of Windows Server include the interface. The interface is so easy and friendly. I know the Linux environment, but I think the user interface of Windows Server is the best.
Our customers use the Active Directory integration in Windows Server, and our application connects to this Active Directory.
What needs improvement?
I don't have experience with Windows Server containers and Kubernetes for deploying cloud-native applications.
I cannot provide specific improvements for Windows Server because I don't have extensive experience with Hyper-V operations. I have only completed two tests.
For how long have I used the solution?
I have 10 to 15 years of experience with Windows Server. I have worked with versions since 2008, 2012, 2016, and the current version 2019.
How are customer service and support?
I don't use or have had any contact with Microsoft support in the last few years.
How would you rate customer service and support?
Neutral
What was our ROI?
In this case, it saves money.
Regarding the amount saved, I would estimate the resource savings to be about 50 to 70%, approximately 60%.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing or licensing for Windows Server, there are options for CPU or core numbers. There are licensing options for on-premise and other options available in the cloud.
I think the pricing is expensive because if you know how to administer or manage Linux, a file server is cheaper to use. However, if you know how to administer Linux, then Windows Server is still the best option for its friendly interface.
Which other solutions did I evaluate?
I am familiar with Hyper-V technology but I tested it some years ago. I am currently using Oracle VM VirtualBox, and the other option is VMware.
I am referring to Hyper-V technology within Windows Server.
What other advice do I have?
We are a Lenovo administrator and purchased a Lenovo server five or six years ago.
In the company, we have five servers with Windows Server and we are users of Microsoft 365, and we use other Microsoft Office software.
The main cloud provider for Windows Server is Nexus.
Some customers use enterprise version, while others are standard version users.
We have services for other companies in different business sectors including finance, education, and manufacturing.
We are not managing the Active Directory services; we are just users for this security. Our application connects to the customer's Active Directory and validates credentials with this service.
We have Windows Defender on laptops without needing any other tools.
We have sensitive information at our organization, and we maintain a backup on Amazon for this information.
For documentation, I find resources on the internet, YouTube, and Microsoft Docs, as there is extensive information available online.
I receive help from colleagues in the office, as some collaborators and employees manage this information and administration.
My company acts as resellers for Microsoft. For selling licenses for Windows Server or other Microsoft products, we contact Nexus, which is the big partner for Microsoft.
I would rate Windows Server eight out of ten.
Windows Server boosts file sharing efficiency and simplifies permission management
What is our primary use case?
The main use cases for Windows Server involve file sharing, such as file server and network shares. We are not a big organization using Windows Server . We are in the transportation industry, and we have a data center. We have approximately 15 servers and 50 machines, some of them are virtual.
How has it helped my organization?
The Active Directory integration helps my organization manage permissions and maintain security policies effectively. The security groups are perfect for what I need. I can give groups of users access to specific subfolders easily through the AD security group instead of adding users individually. You simply add them to a security group and the rest of it follows. This is a good mechanism.
It definitely saves my team a lot of time. It's hard to say exactly how much time it saves, but imagine you need to add five new users to a share. Instead of going in, logging in, and finding the user, I just add the members to the group. Click okay, apply, and they have access to the network shares. I don't even need to access the server directly, which is a nice part of it.
What is most valuable?
The best features of Windows Server are that it works and gives us everything we need to share files and set security permissions. It is done effectively in terms of the NTFS permissions. I can base them on AD security groups.
I have utilized the Active Directory integration in Windows Server for identity management, and they are on a domain.
What needs improvement?
We haven't utilized Windows containers and Kubernetes for deploying any applications. I'm trying to learn it and have started to watch YouTube content for my understanding.
I cannot tell if the security enhancements such as Windows Defender Advanced Threat Protection have contributed to protecting sensitive data.
We have not implemented the failover clustering feature in Windows Server.
For how long have I used the solution?
I have experience with Windows Server for approximately four to five years.
What do I think about the stability of the solution?
In terms of stability, I would say it's good. Looking at Windows Server 2025, there are still bugs to fix, but 2019 has been there for years and is pretty stable. It's doing a very good job.
What do I think about the scalability of the solution?
I think Windows Server does a very good job with scalability. From what I've read, it can scale out easily.
How are customer service and support?
I have not dealt with Microsoft customer service or technical support directly. My colleague worked with them, and they were available and helped fix the issue. It worked.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I assess the impact of Hyper-V technology on our resource utilization and hardware costs as very attractive after Broadcom killed VMware for small companies. That's why I'm looking at other technologies and what people say about them.
How was the initial setup?
The initial setup of Windows Server is straightforward in my opinion. It comes with lots of features or things by default. It's already set up with a certain level of security and other things that require hardening based on our company policies, but it's straightforward. It's doing its job and comes ready to continue the setup.
What other advice do I have?
I do not have experience with Azure products or Citrix. I'm getting to know what other people are saying about the product.
I do not deal with any other types of products such as Cisco, Fortinet, Palo Alto, or testing tools. I just work with Windows Server.
I do not deal with other products such as Windows Server AppFabric or WSUS , Windows Server Update Services . It's an old-style pure server, on-premises, physical.
I use patch management, such as the update services. We do have it, but it's not me who's taking care of it.
I see lots of new features that Microsoft brings into Windows Server 2025. I understand it's not ready for a general release yet. It's definitely very interesting with the new features and focused a lot on the cloud part of it, so it's something to explore.
I can't say which specific feature I'm most looking forward to seeing since I don't deal with cloud. I don't have it in my environment, but I'm trying to learn it. I'm keeping up with my reading about it, so once I have a better understanding, maybe we can try something.
I am still a system administrator with TFI International.
On a scale of 1-10, I rate Windows Server a 9.
Efficient Management Achieved with Internal Resources and Reliable Technical Support
What is our primary use case?
My purpose for using Windows Server