Your company plans to deploy Microsoft Defender for Cloud to secure a multi-cloud environment that includes Azure, AWS, and GCP. You need to ensure that security recommendations from all three cloud providers are centrally visible. What should you configure?
The native way to extend Defender for Cloud to AWS and GCP is the multicloud connectors feature: for AWS you create a CloudFormation stack that provisions a role with the required read permissions, and for GCP you create a service account and project binding. Once connected, Defender for Cloud automatically aggregates security recommendations, regulatory compliance scores (CIS, PCI DSS, etc.), and workload protection plans across Azure, AWS, and GCP in the same portal blade. This is the intended first-class mechanism and does not require Azure Arc or Sentinel.
Why this answer
The correct option is A: onboarding AWS and GCP accounts to Microsoft Defender for Cloud using the multicloud connectors feature. This is the native capability that lets Defender for Cloud pull security posture and recommendations from AWS and GCP into the same central dashboard as Azure, giving a unified view across all three clouds. Option B is wrong because Azure Policy and Azure Arc govern and configure resources but do not aggregate AWS/GCP security recommendations into Defender for Cloud.
Option C is wrong because Microsoft Sentinel is a SIEM/SOAR for log ingestion and workbooks, not the mechanism that surfaces Defender for Cloud recommendations. Option D is wrong because AWS Security Hub and Google Cloud Security Command Center are separate provider-native tools and do not provide a single centralized Defender for Cloud view.