This product has charges associated with it for security hardening and compliance alignment. Madarson IT hardened Windows Server 2022 AMI - pre-configured for NIST CSF, PCI DSS, and HIPAA compliance. Deploy a security-optimized EC2 instance ready for regulated workloads.
Madarson IT Hardened Windows Server 2022 - Advanced Security
This is a repackaged software product wherein additional charges apply for security hardening, compliance alignment, and ongoing maintenance of this image.
Deploy a production-ready, advanced hardened Windows Server 2022 EC2 instance that helps regulated organizations achieve compliance faster. This AMI applies advanced security controls beyond baseline hardening, reducing your attack surface and accelerating audit readiness for frameworks including NIST CSF, ISO 27000, PCI DSS, and HIPAA.
Key Features
Advanced Security Hardening: Implements comprehensive hardening controls that go beyond baseline by enforcing stricter access policies, disabling unnecessary services, and tightening system configurations for environments handling sensitive data.
Compliance Framework Mapping: Controls map to NIST Cybersecurity Framework (CSF), ISO 27000 series, PCI DSS, and HIPAA requirements, helping your security team demonstrate alignment during audits.
Pre-Applied Security Updates: The image ships with the latest Microsoft security patches applied, reducing the window of exposure to known vulnerabilities.
Reduced Attack Surface: Legacy protocols and unnecessary Windows features are disabled out of the box, limiting potential entry points for unauthorized access, denial of service, and other cyber threats.
Robust Access Controls: Stringent local security policies, account lockout configurations, and audit logging settings are pre-configured to enforce least-privilege principles.
Use Case: Regulated Industry Deployments
A healthcare organization deploying electronic health record (EHR) systems on AWS can use this hardened AMI as the foundation for HIPAA-compliant Windows workloads. Financial services firms processing payment data can leverage the advanced hardening controls to satisfy PCI DSS requirements for Windows-based application servers, reducing the manual hardening effort from days to minutes.
Technical Details
Operating System: Windows Server 2022 Base
Hardening Standard: Advanced security hardening mapped to industry compliance frameworks
AWS Integration: Launches as a standard EC2 instance; compatible with AWS Systems Manager for ongoing patch management and compliance monitoring
Deployment: Launch directly from AWS Marketplace; the image is hardened and ready to use immediately after boot
What Advanced Hardening Includes
Advanced security controls are intended for environments where security takes priority over ease of use. Compared to a baseline image, this advanced configuration applies additional restrictions including tighter network protocol settings, more aggressive audit policies, enhanced user rights assignments, and stricter Windows Firewall rules. These controls are designed for servers handling sensitive or regulated data where a higher security posture is required.
Important Notes
This image provides a strong security baseline. Organizations should review applied controls against their specific requirements, as some advanced settings may restrict functionality needed for certain workloads.
Madarson IT certified images are built to be up to date, secure, and aligned with industry standards, working right out of the box.
To request a detailed hardening benchmark report or discuss compliance requirements, contact Madarson IT through the support channels listed on this page.
Disclaimer: Windows Server is a trademark of Microsoft Corporation. This offering is provided by Madarson IT and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation.
Highlights
Advanced Security Hardening for Windows Server 2022: Implements advanced controls beyond baseline - including stricter access policies, disabled legacy protocols, aggressive audit logging, and tightened Windows Firewall rules. Designed for servers handling sensitive or regulated data where security takes priority over convenience, reducing attack surface from first boot without manual configuration.
Compliance Framework Alignment for Regulated Industries: Controls map to NIST Cybersecurity Framework (CSF), ISO 27000 series, PCI DSS, and HIPAA requirements. Healthcare organizations deploying HIPAA-compliant workloads and financial services firms meeting PCI DSS audit requirements can use this image as a pre-hardened foundation, reducing manual configuration from days to minutes.
Deploy-Ready with Pre-Applied Security Updates: Launch a hardened EC2 instance from AWS Marketplace with the latest Microsoft security patches already applied. Unnecessary Windows features and services are disabled, and robust local security policies enforce least-privilege access from first boot - no additional hardening effort required before running regulated workloads.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for this hardened Windows Server 2022 image, based on the EC2 instance type you choose. The many dimensions are not tiers or feature levels. They map to different instance sizes and families, such as general-purpose (m, t), compute-optimized (c), memory-optimized (r, x), storage-optimized (d, i, h), and GPU (g, p) instances. Larger instances carry more CPU, memory, or acceleration, so their hourly rate is higher. The software is identical across all instances. You match the instance to your workload, and hourly billing scales with your running time.
Top-of-mind questions for buyers
Am I charged for the software when an instance is stopped or powered off?
Hourly software charges apply only while the instance runs. A fully stopped instance stops accruing the hourly software rate. You may still pay AWS for attached storage, such as EBS volumes, but the software licence meters running time only.
What am I actually paying for in the hourly rate beyond the compute instance?
The rate covers a hardened Windows Server 2022 image with advanced security configuration. It aligns with recognized security and compliance frameworks and receives regular patch and configuration updates. The instance type you pick sets the compute, memory, or GPU resources underneath.
If I switch to a different instance type, does my rate change automatically?
Yes. Each instance type carries its own hourly rate. When you launch or resize to a different type, billing follows the rate for the type currently running. The change is not a plan upgrade; it simply reflects which instance you run at that time.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Hardened Windows Server 2022 Base image - Level 2: Advanced.
Additional details
Usage instructions
Allow RDP access in your security group
Access the ec2 with the username: Administrator
To connect to the Instance:
Allow inbound RDP access in your security group (TCP port 3389)
Sign in to the AWS Management Console, open the Amazon EC2 console, and choose your Windows Server instance.
Then, select Connect, then Get Password, and then Choose File (private key of the ec2 instance).
Connect to the instance: Use Remote Desktop Connection (RDP) to connect to the instance.
Access the ec2 with the default username: "Administrator" and the password provided
You can also use Systems Manager (SSM) to access the Windows ec2 instance
For questions about this hardened Windows Server 2022 AMI, including deployment assistance, compliance inquiries, or private offers, contact Madarson IT at info@madarsonit.com.
Support scope includes:
Guidance on hardening configuration and applied security controls
Assistance with compliance mapping for NIST CSF, ISO 27000, PCI DSS, and HIPAA
Private offer requests for volume or enterprise deployments
Troubleshooting image-specific issues
When contacting support, please include your AWS account ID and the EC2 instance ID if reporting a technical problem.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2019 AMI with advanced security controls applied - deploy audit-ready EC2 instances mapped to NIST CSF, PCI DSS, and HIPAA from day one.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2022 AMI helps compliance teams achieve audit-readiness on day one, eliminating manual hardening for NIST CSF, PCI DSS, and HIPAA workloads.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT Level 1 hardened Windows Server 2025 Core AMI - pre-configured for regulatory compliance, headless operation, and automation-first cloud workloads on AWS.
This product has charges associated with it for STIG security hardening. AWS EC2 image based on the latest Windows Server 2022 Base build, pre-configured to support DISA STIG compliance. Designed for U.S. Government, Department of Defense, and federal contractor workloads where elevated security baselines and the standard DoD warning banner are required from day one.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.