This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2025 Core AMI aligned to DISA STIG and NIST 800-53 - built for regulated, automation-first environments.
Madarson IT Windows Server 2025 Core - Level 2 Hardened AMI
This is a repackaged software product wherein additional charges apply for security hardening, compliance alignment, and ongoing maintenance of this image.
Deploy a production-ready, compliance-aligned Windows Server 2025 Core instance with Level 2 security hardening pre-applied. This AMI enforces elevated security controls aligned to PCI DSS, HIPAA, DISA STIG, and NIST 800-53 - reducing manual hardening effort and accelerating time-to-compliance for regulated workloads.
What You Get
Level 2 security hardening pre-configured - Stricter defaults, disabled non-essential services, and defense-in-depth measures applied before launch
GUI-free, headless design - No desktop experience or RDP enabled by default, minimizing attack surface
EC2Launch v2 pre-installed and validated - Ready for automated provisioning workflows
Hardened registry, firewall, and access policies - Restrictive configurations applied across all layers
Current security patches applied - Image built with latest available Microsoft security updates
AWS-native integration - Compatible with AWS Systems Manager, License Manager, and EC2 Image Builder
Getting Started
Launch the AMI from AWS Marketplace into your target VPC
Connect via AWS Systems Manager Session Manager (recommended) - Ensure the instance has an IAM role with the AmazonSSMManagedInstanceCore policy attached and outbound HTTPS connectivity to SSM endpoints
Alternatively, use WinRM over HTTPS - Configure security group rules to allow inbound port 5986 from your management network
Validate hardening - Run your compliance scanning tool (e.g., AWS Inspector, Qualys, or Nessus) against the running instance to confirm Level 2 controls are intact
Integrate with your automation pipeline - Use DSC, Ansible, or PowerShell for ongoing configuration management
Prerequisites: VPC with internet or VPC endpoint connectivity to AWS Systems Manager, an IAM instance profile with SSM permissions, and a security group configured for your chosen remote management method.
Use Cases
Regulated Workloads - HIPAA, PCI DSS, FedRAMP, and ISO 27001 environments requiring pre-hardened infrastructure
Zero-Trust Infrastructure - Hardened Core VMs for bastion, jump host, or gateway roles
Security-Sensitive Automation - DSC, Ansible, and PowerShell-driven deployments with strict controls
Container Hosts - ECS-optimized Core base for Windows containers with minimal footprint
CI/CD Build Agents - Secure, ephemeral build environments with no GUI dependencies
Compliance Alignment
This image is configured with controls mapped to:
PCI DSS requirements for system hardening
HIPAA technical safeguards
DISA STIG for Windows Server
NIST 800-53 security control families (AC, AU, CM, SC, SI)
Why Madarson IT
Madarson IT certified Core images are built specifically for organizations that need compliance-ready infrastructure without manual hardening effort. Each image is maintained with current security patches, validated against Level 2 benchmarks, and optimized for headless, automation-driven deployments on AWS.
Hardening Scope
The following categories of hardening are applied beyond a stock Windows Server 2025 Core installation:
Unnecessary Windows services disabled
Registry keys hardened for security-sensitive settings
Windows Firewall configured with restrictive inbound/outbound rules
User rights assignments and security options tightened
Audit policies configured for comprehensive event logging
For detailed compliance mapping documentation or a hardening checklist, contact Madarson IT at info@madarsonit.com.
Disclaimer: Windows Server is a trademark of Microsoft Corporation. This offering is provided by Madarson IT and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation.
Highlights
Level 2 security hardening pre-applied to Windows Server 2025 Core, aligned to PCI DSS, HIPAA, DISA STIG, and NIST 800-53. GUI-free, headless configuration with RDP disabled by default eliminates unnecessary attack vectors. Hardened registry settings, restricted access policies, enhanced firewall rules, and disabled non-essential services reduce the exploitable surface compared to a stock Windows Server Core installation.
AWS-native integration with Systems Manager, License Manager, and EC2 Image Builder enables automated provisioning, compliance monitoring, and image lifecycle management. EC2Launch v2 is pre-installed and validated. Connect securely via SSM Session Manager or WinRM over HTTPS - no GUI dependencies required for full remote administration and automation workflows.
Purpose-built for regulated and high-security environments including finance, healthcare, government, and SaaS infrastructure. Supports zero-trust architectures as bastion or gateway hosts, Windows container workloads on ECS, CI/CD build agents, and DSC/Ansible/PowerShell-driven automation pipelines where strict security controls and compliance alignment are non-negotiable requirements.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for this hardened Windows Server 2025 Core image, billed only while an instance runs. The price you pay depends on the EC2 instance type you choose. Each dimension maps to a specific instance size and family, from small general-purpose types like t3.nano and t2.micro up to memory-, compute-, storage-, and GPU-optimized types like r5a.16xlarge, c5a.16xlarge, d3.8xlarge, and p5.4xlarge. Larger instances with more CPU, memory, or GPU capacity carry higher hourly rates. You run only the instance types your workload needs, with no upfront commitment.
Top-of-mind questions for buyers
What does one hourly unit cover on this listing?
One unit is one running EC2 instance of the chosen type, billed per hour. The rate covers the hardened Windows Server 2025 Core software licence on that instance. You pick the instance family and size, and each running instance meters its own hours separately.
Am I charged when an instance is stopped or powered off?
Software charges apply only while the instance runs. A stopped or powered-off instance stops accruing the hourly software fee. Underlying AWS storage costs for the disk may still apply separately, but the software licence meters running time only.
What compliance hardening is built into this image across all instance types?
Every instance type runs the same Level 2 hardened Windows Server 2025 Core image. It aligns with DISA STIG, PCI-DSS, HIPAA, and NIST frameworks. The image receives regular security patches and compliance updates, so hardening does not change based on the instance size you select.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Secure Windows 2025 Core - Level 2 Hardened AMI for High-Security Workloads
Additional details
Usage instructions
This image is built on Windows Server Core and does not include a desktop experience. Customers can access and manage the instance using:
AWS Systems Manager (SSM)
. No need for public IP or open ports
. Secure shell access via AWS Console or CLI
. Requires IAM role with AmazonSSMManagedInstanceCore
PowerShell Remoting (WinRM)
. Enable TCP port 5985 in your security group
. Connect using Enter-PSSession from a remote PowerShell session
Windows Admin Center (Optional)
. Install WAC on a local machine or gateway VM
. Connect via WinRM for GUI-based remote management
For technical support, compliance inquiries, or private offers, contact Madarson IT at info@madarsonit.com.
Support scope includes:
Guidance on connecting to the hardened AMI (SSM Session Manager, WinRM)
Questions about hardening configurations and compliance alignment
Assistance with compatibility issues caused by Level 2 hardening settings
Private offer requests and volume licensing inquiries
Compliance documentation and audit support requests
Please include your AWS Account ID and instance details when reporting technical issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT Level 1 hardened Windows Server 2025 Core AMI - pre-configured for regulatory compliance, headless operation, and automation-first cloud workloads on AWS.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT hardened Windows Server 2022 AMI - pre-configured for NIST CSF, PCI DSS, and HIPAA compliance. Deploy a security-optimized EC2 instance ready for regulated workloads.
This product has charges associated with it for STIG security hardening. AWS EC2 image based on the latest Windows Server 2022 Base build, pre-configured to support DISA STIG compliance. Designed for U.S. Government, Department of Defense, and federal contractor workloads where elevated security baselines and the standard DoD warning banner are required from day one.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2019 AMI with advanced security controls applied - deploy audit-ready EC2 instances mapped to NIST CSF, PCI DSS, and HIPAA from day one.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.