Skip to content

AWS ↔ Azure cross-reference

Conceptual mapping for fast navigation; services are not always feature-identical.

Need AWS Azure
Control-plane audit CloudTrail management events Azure Activity Log
Identity provider IAM / IAM Identity Center Microsoft Entra ID
Role/session use STS AssumeRole Role assignment, PIM activation, token/sign-in context
Managed threat findings GuardDuty Microsoft Defender for Cloud
Network flow VPC Flow Logs NSG flow logs / virtual-network flow logs where enabled
Object storage S3 Blob Storage
Secrets/keys Secrets Manager / KMS Key Vault
Compute EC2 Virtual Machines
Serverless Lambda Azure Functions
Resource organization Account / Organizations Subscription / Management Groups
Monitoring/query CloudWatch / CloudTrail Lake Azure Monitor / Log Analytics
AWS: identity → API event → ARN/resource → region/account → sequence
Azure: identity → operation → resource ID → subscription/tenant → sequence