This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2019 AMI - deploy audit-ready EC2 instances mapped to NIST CSF, PCI DSS, and HIPAA frameworks in minutes.
Madarson IT Hardened Windows Server 2019 - Foundational Security
This is a repackaged software product wherein additional charges apply for security hardening, compliance alignment, and ongoing maintenance of this image.
Eliminate weeks of manual OS hardening and reduce audit preparation time by deploying a pre-hardened Windows Server 2019 AMI with foundational security controls applied. This image is designed for IT security teams, compliance engineers, and cloud architects who need to launch secure, audit-ready EC2 instances without configuring hundreds of security settings by hand.
Who This Image Is For
Healthcare organizations needing HIPAA technical safeguard compliance for patient-facing applications
E-commerce and retail teams handling cardholder data under PCI DSS requirements
Financial services firms aligning with NIST Cybersecurity Framework controls
Mid-market IT teams without dedicated security staff who need a compliant baseline fast
Key Capabilities
Foundational security hardening - Controls applied across account policies, audit policies, user rights assignments, security options, and Windows Firewall settings
Multi-framework alignment - Configuration maps to NIST Cybersecurity Framework (CSF), ISO 27000 series, PCI DSS, HIPAA, and other regulatory frameworks
Regular updates - Image maintained with current security patches and hardening rule updates
Ready to deploy - Launch directly from AWS Marketplace with no additional hardening scripts required
Deployment Overview
Subscribe to the AMI through AWS Marketplace
Launch an EC2 instance using your preferred instance type
Connect via RDP using your EC2 key pair credentials
Validate hardening by reviewing applied security policies in Local Security Policy
Customize additional settings based on your organization's specific security requirements
The image works within standard AWS VPC configurations and supports integration with AWS Systems Manager for ongoing patch management and compliance monitoring.
Use Case: Healthcare Compliance
A healthcare organization deploying patient-facing applications on Windows Server 2019 can use this image to meet HIPAA technical safeguard requirements without manual OS hardening. The pre-applied foundational controls address access management, audit logging, and network protection - reducing the gap between deployment and compliance readiness.
Use Case: PCI DSS Environments
Retail and e-commerce teams processing payment card data can deploy this hardened image as their server baseline, addressing multiple PCI DSS requirements for system hardening (Requirement 2) and access control (Requirement 7) from the first boot.
Why Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Our hardening process applies comprehensive foundational controls to reduce your attack surface and provide a documented security baseline that auditors recognize.
Important Notes
This image applies foundational hardening controls, which are designed to be broadly applicable without significant performance impact
Organizations with stricter requirements may need to apply additional controls or custom policies
Certain Windows Server roles or features may require configuration adjustments after hardening is applied
Review the applied hardening controls against your specific compliance requirements before production deployment
Disclaimer: Windows Server is a trademark of Microsoft Corporation. This offering is provided by Madarson IT and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation.
Highlights
Foundational security controls pre-applied to Windows Server 2019, mapping to NIST Cybersecurity Framework (CSF), ISO 27000 series, PCI DSS, HIPAA, and other regulatory frameworks. Deploy audit-ready EC2 instances directly from AWS Marketplace without spending weeks on manual OS hardening. Ideal for healthcare, financial services, retail, and organizations needing documented compliance baselines.
Hardening reduces your attack surface by restricting unauthorized access, disabling unnecessary services, enforcing least-privilege account policies, configuring Windows Firewall rules, and applying stringent audit policies. These foundational controls address common cyber threats including unauthorized access, denial of service, and privilege escalation - providing a security baseline that auditors recognize.
Ready to deploy with no additional hardening scripts required. Madarson IT certified images are maintained with current security patches and hardening updates. Launch, connect via RDP, and validate applied security policies immediately. Supports integration with AWS Systems Manager for ongoing patch management and compliance monitoring.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for this hardened Windows Server 2019 image, billed per running instance. Pricing is not tiered by feature. Instead, each dimension maps to a specific AWS EC2 instance type, so your rate depends on the compute size you pick. General-purpose (m, t), compute-optimized (c), memory-optimized (r, x), storage-optimized (d, i, h), GPU (g, p), and HPC (hpc) families are all listed. Larger instance sizes carry higher hourly rates. You can run any listed instance size and switch as your workload needs change. Software charges apply on top of standard AWS infrastructure costs.
Top-of-mind questions for buyers
What does one hourly unit cover for this hardened image?
One unit is one running EC2 instance of the chosen type, billed per hour. The rate covers the software licence for the hardened Windows Server 2019 image on that instance size. You pay separately for AWS compute, storage, and network usage. Each running instance meters its own hours.
Am I charged the software fee when an instance is stopped or paused?
The software charge meters running instance-hours only. A stopped or powered-off instance does not accrue software charges. You may still pay underlying AWS storage fees for attached volumes while the instance is stopped, but the hardened image licence bills active running time.
What security hardening is included, and does it change my hourly rate?
The image ships pre-configured to a Level 1 Foundational baseline aligned with common security and compliance frameworks. This hardening is built into every listed instance type. Your hourly rate reflects only the instance size you pick, not the hardening level, which is the same across all dimensions.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Hardened Windows Server 2019 Base image with Level 1: Foundational.
Additional details
Usage instructions
Allow RDP access in your security group
Access the ec2 with the username: Administrator
To connect to the Instance:
Allow inbound RDP access in your security group (TCP port 3389)
Sign in to the AWS Management Console, open the Amazon EC2 console, and choose your Windows Server instance.
Then, select Connect, then Get Password, and then Choose File (private key of the ec2 instance).
Connect to the instance: Use Remote Desktop Connection (RDP) to connect to the instance.
Access the ec2 with the default username: "Administrator" and the password provided
You can also use SSM to access the ec2
For technical questions, hardening configuration inquiries, compliance guidance, or private offers, contact Madarson IT at info@madarsonit.com.
Support scope includes:
Questions about applied hardening controls and their configuration
Guidance on customizing the hardened image for your specific compliance requirements
Assistance with post-deployment validation and compliance scanning
Private offer requests and volume licensing inquiries
Audit documentation and compliance mapping questions
After subscribing through AWS Marketplace, launch an EC2 instance and connect via RDP using your EC2 key pair. If you encounter any issues during deployment or need help validating the applied security controls, contact the team at the email above.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2019 AMI with advanced security controls applied - deploy audit-ready EC2 instances mapped to NIST CSF, PCI DSS, and HIPAA from day one.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2022 AMI helps compliance teams achieve audit-readiness on day one, eliminating manual hardening for NIST CSF, PCI DSS, and HIPAA workloads.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT hardened Windows Server 2022 AMI - pre-configured for NIST CSF, PCI DSS, and HIPAA compliance. Deploy a security-optimized EC2 instance ready for regulated workloads.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT Level 1 hardened Windows Server 2025 Core AMI - pre-configured for regulatory compliance, headless operation, and automation-first cloud workloads on AWS.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.