This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Windows Server 2019 AMI with advanced security controls applied - deploy audit-ready EC2 instances mapped to NIST CSF, PCI DSS, and HIPAA from day one.
Madarson IT Hardened Windows Server 2019 - Advanced Security
This is a repackaged software product wherein additional charges apply for security hardening, compliance alignment, and ongoing maintenance of this image.
Deploy a production-ready, advanced hardened Windows Server 2019 EC2 instance that helps regulated organizations achieve compliance faster. This AMI eliminates the manual effort of hardening a fresh Windows Server deployment - saving days of configuration work while ensuring consistent, repeatable security baselines across your AWS environment.
Who Is This For?
This AMI is purpose-built for organizations operating in compliance-driven environments:
Healthcare IT teams needing HIPAA-compliant Windows workloads for electronic health record systems and clinical applications
Financial services security engineers meeting PCI DSS requirements for cardholder data environments
Government contractors and agencies requiring pre-hardened base images aligned with NIST Cybersecurity Framework controls
Mid-market organizations lacking dedicated hardening expertise who need enterprise-grade security out of the box
What Advanced Hardening Delivers
Advanced security controls go beyond foundational hardening for high-security environments where confidentiality takes priority. Advanced hardening includes:
Stricter audit and logging policies that capture detailed security events for forensic analysis
More restrictive user rights assignments and security options
Enhanced network protocol restrictions and disabled legacy services
Tighter password policies and account lockout configurations
Additional Windows Firewall rules and service disablement
Restricted remote access configurations and elevated authentication requirements
Compliance Framework Mapping
The hardening controls applied in this image map to established standards and regulatory frameworks, including:
NIST Cybersecurity Framework (CSF) - Identify, Protect, and Detect function controls
ISO 27000 series - Information security management controls
PCI DSS - System hardening and access control requirements
HIPAA - Technical safeguard controls for protected health information
Key Security Controls Applied
Disabled unnecessary Windows services and features to reduce attack surface
Configured Windows audit policies for comprehensive event logging
Enforced strong password and account lockout policies
Restricted network protocols and disabled legacy authentication methods
Applied registry-level security settings per hardening guidance
Configured User Rights Assignments to principle of least privilege
Hardened Windows Firewall with restrictive inbound and outbound rules
AWS Integration
This AMI is designed for deployment on AWS EC2 instances. Launch the image in your VPC, apply your organization-specific configurations on top of the hardened baseline, and integrate with AWS services such as CloudWatch for monitoring, AWS Systems Manager for patch management, and AWS Config for compliance tracking.
Important Considerations
This image provides OS-level hardening only. Application-layer security, data encryption at rest, and network architecture remain the buyer's responsibility.
Some Windows roles or features may be disabled by hardening controls. Organizations should test application compatibility in a non-production environment before deploying to production.
The hardened baseline should be considered a strong starting point. Organizations may need to customize settings based on their specific risk profile and operational requirements.
Regular patching and updates remain the responsibility of the deploying organization after launch.
Why Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Every image undergoes rigorous configuration and validation to ensure security controls are properly applied before publication.
Disclaimer: Windows Server is a trademark of Microsoft Corporation. This offering is provided by Madarson IT and is not affiliated with, endorsed by, or sponsored by Microsoft Corporation.
Highlights
Maps to NIST Cybersecurity Framework (CSF), ISO 27000 series, PCI DSS, and HIPAA regulatory frameworks. Advanced controls go beyond foundational hardening with stricter audit policies, restricted user rights, disabled legacy services, and enhanced network protocol restrictions - designed for high-security environments where confidentiality is the priority.
Eliminates days of manual hardening effort by delivering a pre-configured, audit-ready Windows Server 2019 baseline. Security engineers and compliance teams can launch a hardened EC2 instance and immediately begin layering application-specific configurations on top, rather than starting from a default Windows installation and applying hundreds of individual security settings.
Reduces attack surface by disabling unnecessary Windows services, enforcing least-privilege user rights assignments, configuring comprehensive audit logging, and applying restrictive firewall rules. Protects against unauthorized access, denial of service, and advanced persistent threats through defense-in-depth controls applied at the operating system layer.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for this hardened Windows Server 2019 image, billed per running instance. The many dimensions are not tiers or feature levels. Each one maps to a specific Amazon EC2 instance type you choose to run. Your hourly software rate depends on the instance size and family you select, such as general-purpose (m-series, t-series), compute-optimized (c-series), memory-optimized (r-series, x-series), storage-optimized (d-series, i-series), or GPU/accelerated (g-series, p-series). Larger instances carry higher hourly rates. EC2 infrastructure charges apply separately. Volume licensing and private offers are available for enterprise and government buyers.
Top-of-mind questions for buyers
What does one hourly unit cover, and what is not included in that rate?
Each hourly rate covers the hardened Windows Server 2019 software license for one running EC2 instance of the type you select. Amazon EC2 infrastructure charges, storage, and data transfer bill separately through AWS. The software rate applies per instance-hour, so ten running instances accrue ten times the hourly software charge.
Am I charged the software rate when my instance is stopped?
The software rate meters running instance-hours only. A fully stopped instance does not accrue the hourly software charge. Underlying AWS storage fees for the attached volumes may still apply while the instance is stopped, but those are separate from the software license.
How does my hourly cost change if I switch to a different instance type?
Each dimension maps to a specific EC2 instance type. Your software rate follows the instance family and size you run, such as general-purpose, compute-optimized, memory-optimized, storage-optimized, or GPU. Larger instances carry higher hourly rates. Switching types changes your rate automatically for the new running instance.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Hardened Windows Server 2019 Base image - Level 2: Advanced.
Additional details
Usage instructions
Allow RDP access in your security group
Access the ec2 with the username: Administrator
To connect to the Instance:
Allow inbound RDP access in your security group (TCP port 3389)
Sign in to the AWS Management Console, open the Amazon EC2 console, and choose your Windows Server instance.
Then, select Connect, then Get Password, and then Choose File (private key of the ec2 instance).
Connect to the instance: Use Remote Desktop Connection (RDP) to connect to the instance.
Access the ec2 with the default username: "Administrator" and the password provided
You can also use Systems Manager (SSM) to access the Windows ec2 instance
For questions about this hardened Windows Server 2019 AMI, including configuration guidance, compliance inquiries, or private offers, contact Madarson IT at info@madarsonit.com.
Support scope includes:
Hardening configuration questions and customization guidance
When contacting support, please include your AWS account ID and the EC2 instance ID if reporting a technical problem.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Ubuntu 24.04 LTS virtual desktop AMI with pre-configured GUI/RDP access, mapped to NIST CSF, PCI DSS, and HIPAA frameworks for production compliance.
This product has charges associated with it for RDP/GUI optimization. Madarson IT pre-configured RHEL 9 cloud virtual desktop AMI with RDP/GUI optimization - launch and connect to a graphical Linux desktop in minutes.
This product has charges associated with it for security hardening and compliance alignment. Madarson IT pre-hardened Ubuntu 22.04 LTS virtual desktop with GUI and RDP access, aligned to NIST CSF, PCI DSS, and HIPAA frameworks for secure cloud workstations.
This product has charges associated with it for DISA STIG security hardening. Madarson IT pre-hardened Ubuntu 24.04 LTS AMI with DISA STIG benchmarks applied. Deploy a compliance-ready EC2 instance for DoD and federal security requirements.
This product has charges associated with it for Level 1 foundational security hardening. Madarson IT pre-hardened RHEL 9 AMI delivers a deploy-ready security baseline mapped to NIST CSF, PCI DSS, HIPAA, and ISO 27000 - reducing manual hardening effort for compliance-driven teams.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.