Listing Thumbnail

    Madarson IT Windows Server 2025 Core Level 2 Hardened AMI

     Info
    Sold by: Madarson IT 
    Deployed on AWS
    AWS Free Tier
    This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2025 Core AMI aligned to DISA STIG and NIST 800-53 - built for regulated, automation-first environments.

    Overview

    Open image

    Madarson IT Windows Server 2025 Core - Level 2 Hardened AMI

    This is a repackaged software product wherein additional charges apply for security hardening, compliance alignment, and ongoing maintenance of this image.

    Deploy a production-ready, compliance-aligned Windows Server 2025 Core instance with Level 2 security hardening pre-applied. This AMI enforces elevated security controls aligned to PCI DSS, HIPAA, DISA STIG, and NIST 800-53 - reducing manual hardening effort and accelerating time-to-compliance for regulated workloads.

    What You Get

    • Level 2 security hardening pre-configured - Stricter defaults, disabled non-essential services, and defense-in-depth measures applied before launch
    • GUI-free, headless design - No desktop experience or RDP enabled by default, minimizing attack surface
    • EC2Launch v2 pre-installed and validated - Ready for automated provisioning workflows
    • Hardened registry, firewall, and access policies - Restrictive configurations applied across all layers
    • Current security patches applied - Image built with latest available Microsoft security updates
    • AWS-native integration - Compatible with AWS Systems Manager, License Manager, and EC2 Image Builder

    Getting Started

    1. Launch the AMI from AWS Marketplace into your target VPC
    2. Connect via AWS Systems Manager Session Manager (recommended) - Ensure the instance has an IAM role with the AmazonSSMManagedInstanceCore policy attached and outbound HTTPS connectivity to SSM endpoints
    3. Alternatively, use WinRM over HTTPS - Configure security group rules to allow inbound port 5986 from your management network
    4. Validate hardening - Run your compliance scanning tool (e.g., AWS Inspector, Qualys, or Nessus) against the running instance to confirm Level 2 controls are intact
    5. Integrate with your automation pipeline - Use DSC, Ansible, or PowerShell for ongoing configuration management

    Prerequisites: VPC with internet or VPC endpoint connectivity to AWS Systems Manager, an IAM instance profile with SSM permissions, and a security group configured for your chosen remote management method.

    Use Cases

    • Regulated Workloads - HIPAA, PCI DSS, FedRAMP, and ISO 27001 environments requiring pre-hardened infrastructure
    • Zero-Trust Infrastructure - Hardened Core VMs for bastion, jump host, or gateway roles
    • Security-Sensitive Automation - DSC, Ansible, and PowerShell-driven deployments with strict controls
    • Container Hosts - ECS-optimized Core base for Windows containers with minimal footprint
    • CI/CD Build Agents - Secure, ephemeral build environments with no GUI dependencies

    Compliance Alignment

    This image is configured with controls mapped to:

    • PCI DSS requirements for system hardening
    • HIPAA technical safeguards
    • DISA STIG for Windows Server
    • NIST 800-53 security control families (AC, AU, CM, SC, SI)

    Why Madarson IT

    Madarson IT certified Core images are built specifically for organizations that need compliance-ready infrastructure without manual hardening effort. Each image is maintained with current security patches, validated against Level 2 benchmarks, and optimized for headless, automation-driven deployments on AWS.

    Hardening Scope

    The following categories of hardening are applied beyond a stock Windows Server 2025 Core installation:

    • Unnecessary Windows services disabled
    • Registry keys hardened for security-sensitive settings
    • Windows Firewall configured with restrictive inbound/outbound rules
    • User rights assignments and security options tightened
    • Audit policies configured for comprehensive event logging
    • Network protocol hardening (SMB, NTLM, TLS settings)
    • Remote access restricted to secure methods only

    For detailed compliance mapping documentation or a hardening checklist, contact Madarson IT at info@madarsonit.com .

    Disclaimer: Windows Server is a trademark of Microsoft Corporation. This offering is provided by Madarson IT and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation.

    Highlights

    • Level 2 security hardening pre-applied to Windows Server 2025 Core, aligned to PCI DSS, HIPAA, DISA STIG, and NIST 800-53. GUI-free, headless configuration with RDP disabled by default eliminates unnecessary attack vectors. Hardened registry settings, restricted access policies, enhanced firewall rules, and disabled non-essential services reduce the exploitable surface compared to a stock Windows Server Core installation.
    • AWS-native integration with Systems Manager, License Manager, and EC2 Image Builder enables automated provisioning, compliance monitoring, and image lifecycle management. EC2Launch v2 is pre-installed and validated. Connect securely via SSM Session Manager or WinRM over HTTPS - no GUI dependencies required for full remote administration and automation workflows.
    • Purpose-built for regulated and high-security environments including finance, healthcare, government, and SaaS infrastructure. Supports zero-trust architectures as bastion or gateway hosts, Windows container workloads on ECS, CI/CD build agents, and DSC/Ansible/PowerShell-driven automation pipelines where strict security controls and compliance alignment are non-negotiable requirements.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Win 2025

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Madarson IT Windows Server 2025 Core Level 2 Hardened AMI

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (65)

     Info
    Dimension
    Cost/hour
    m5a.xlarge
    Recommended
    $0.10
    t3.micro
    $0.05
    t2.micro
    $0.025
    r5a.4xlarge
    $0.40
    i3.xlarge
    $0.10
    c5a.16xlarge
    $1.60
    t3.2xlarge
    $0.20
    m5a.large
    $0.05
    m5a.8xlarge
    $0.80
    t2.2xlarge
    $0.20

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for this hardened Windows Server 2025 Core image, billed only while an instance runs. The price you pay depends on the EC2 instance type you choose. Each dimension maps to a specific instance size and family, from small general-purpose types like t3.nano and t2.micro up to memory-, compute-, storage-, and GPU-optimized types like r5a.16xlarge, c5a.16xlarge, d3.8xlarge, and p5.4xlarge. Larger instances with more CPU, memory, or GPU capacity carry higher hourly rates. You run only the instance types your workload needs, with no upfront commitment.

    Top-of-mind questions for buyers

    One unit is one running EC2 instance of the chosen type, billed per hour. The rate covers the hardened Windows Server 2025 Core software licence on that instance. You pick the instance family and size, and each running instance meters its own hours separately.
    Software charges apply only while the instance runs. A stopped or powered-off instance stops accruing the hourly software fee. Underlying AWS storage costs for the disk may still apply separately, but the software licence meters running time only.
    Every instance type runs the same Level 2 hardened Windows Server 2025 Core image. It aligns with DISA STIG, PCI-DSS, HIPAA, and NIST frameworks. The image receives regular security patches and compliance updates, so hardening does not change based on the instance size you select.
    madarsonit.com
    Helpful?

    Vendor refund policy

    There is no refund policy for this image.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Secure Windows 2025 Core - Level 2 Hardened AMI for High-Security Workloads

    Additional details

    Usage instructions

    This image is built on Windows Server Core and does not include a desktop experience. Customers can access and manage the instance using: AWS Systems Manager (SSM) . No need for public IP or open ports . Secure shell access via AWS Console or CLI . Requires IAM role with AmazonSSMManagedInstanceCore PowerShell Remoting (WinRM) . Enable TCP port 5985 in your security group . Connect using Enter-PSSession from a remote PowerShell session Windows Admin Center (Optional) . Install WAC on a local machine or gateway VM . Connect via WinRM for GUI-based remote management

    Support

    Vendor support

    For technical support, compliance inquiries, or private offers, contact Madarson IT at info@madarsonit.com .

    Support scope includes:

    • Guidance on connecting to the hardened AMI (SSM Session Manager, WinRM)
    • Questions about hardening configurations and compliance alignment
    • Assistance with compatibility issues caused by Level 2 hardening settings
    • Private offer requests and volume licensing inquiries
    • Compliance documentation and audit support requests

    Please include your AWS Account ID and instance details when reporting technical issues.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.