Government Cloud Support Reference
This page has moved
For up-to-date information about AWS Government Cloud Support, go to Government Cloud Overview and Support.
For InsightCloudSec customers interested in details about the configuration of cloud services within the Government Cloud (GovCloud) space, we have created this section of our documentation to organize all GovCloud-specific details.
AWS GovCloud Support
AWS GovCloud Policies
InsightCloudSec offers several different AWS policies for harvesting resource information found in your AWS accounts and enabling InsightCloudSec features. Our universal onboarding experience will implement the appropriate policies automatically, so there's no need for AWS GovCloud-specific policies. Review AWS Policies for details.
AWS GovCloud Supported Deployment Regions
InsightCloudSec can only be deployed in AWS. For self-hosted customers, InsightCloudSec can be exclusively deployed/hosted in AWS GovCloud, if you so choose. For SaaS customers reach out to support for additional details on deployment.
AWS GovCloud Supported Services
Listed below are all of the AWS GovCloud services (and their components) supported by InsightCloudSec. In general if a service is supported by InsightCloudSec for GovCloud, we support it in any region in which the CSP provides the service. If you have questions related to AWS or specific services and their support, contact us through the Customer Support Portal.
text
1Amazon API Gateway (Domain, Key, Stage, Usage Plans)2Amazon DocumentDB3Amazon QuickSight4Amazon SageMaker (Notebook, Training job)5Amazon Simple Email Service (Configuration sets, Rules)6Amazon Redshift (Snapshot)7Amazon Transcription8AppStream 2.09Athena (Workgroup)10AWS Auto Scaling (Group)11AWS Backup (gateway, Vault)12AWS Glue (Data Catalog, Database, Security Configuration)13AWS Health Dashboard14AWS Organizations15Batch (Compute Environment)16Certificate Manager (Private Certificate Authority)17CloudFormation (Templates)18CloudFront19CloudHSM20CloudTrail21CloudWatch (Alarm, Log Group)22Database Migration Service (Endpoint, Replication Instance)23DynamoDB24EC2 (Amazon EBS Snapshot, Amazon EBS Volume,Instance, Launch Template, Reserved Instance, Resource/Service Limit/Quota, Savings Plans, SSH Key Pairs)25EFS26Elastic Beanstalk (Application, Environment)27Elastic Container Registry (Container Registry)28Elastic Container Service/Fargate29Elastic Kubernetes Service (Node Group)30Elastic Load Balancer (Application Load Balancer, Gateway Load Balancer, Network Load Balancer)31ElastiCache (Snapshot)32EMR33FSx34Global Accelerator35IAM (Cloud Account, Group, Policy (Customer Managed), Role, User, User Access Key)36Key Management Service37Kinesis38Lambda (Layer)39Neptune40OpenSearch Service41RDS (Aurora, Cluster, Event Subscription, Instance, fSnapshot)42Region43Route 5344S3 (Access Point)45SAML Identity Provider46Secrets Manager (Secret)47Simple Queue Service48Simple Notification Service (Subscription, Topic)49Step Function State Machine50Storage Gateway51Systems Manager (Document)52Trusted Advisor53VPC (Elastic IP, Elastic Network Interface (ENI), Flow Log, Internet Gateway, NACL/Security Group, NACL/Security Group Rules, NAT Gateway, Peer, Route Table, Subnet)54WAF55WorkSpaces (Instances)
Azure GovCloud Support
Azure GovCloud Roles
🚧 Organization Support
Currently, InsightCloudSec does not offer Organization onboarding support for Azure GovCloud.
For Azure GovCloud accounts, there are two role options (excluding Azure's built-in roles):
Azure GovCloud Custom Reader User Role
If you are interested in operating in read-only mode, which prevents InsightCloudSec from taking actions against your Microsoft Azure GovCloud resources, then we recommend using the Azure GovCloud Custom Reader User role. This role grants InsightCloudSec read-only permissions to supported resources so data is harvested and available for reporting. **Using this role means you must manually update the role with each new Azure GovCloud service that InsightCloudSec supports. **
The role JSON can be obtained from our public S3 bucket. Note: The JSON file includes a placeholder value for the subscription ID. This placeholder value will need to be replaced before implementing the role.
Azure GovCloud Power User Role
If you would like to use InsightCloudSec to manage your Microsoft Azure GovCloud resources directly or through the use of Bots, then use the InsightCloudSec Azure GovCloud Power User role. The InsightCloudSec Azure GovCloud Power User role will grant InsightCloudSec all permissions to supported resources so it can act upon cloud resources in addition to monitoring and reporting on them. **Using this role means you must manually update the role with each new Azure GovCloud service that InsightCloudSec supports. **
The role JSON can be obtained from our public S3 bucket. Note: The JSON file includes a placeholder value for the subscription ID. This placeholder value will need to be replaced before implementing the role.
Azure GovCloud Supported Regions
text
1usgovarizona2usgoviowa3usgovtexas4usgovvirginia
Azure GovCloud Supported Services
Listed below are all of the Azure GovCloud services (and their components) supported by InsightCloudSec. For resource support, in general if a resource is supported by InsightCloudSec for GovCloud, we support it in any region in which the CSP provides the resource. If you have questions related to Azure or specific services and their support, contact us through the Customer Support Portal.
text
1Activity log (Alerts)2API Management services3App Registration4App Services5App Service plans6Application credentials7Application gateways8Automation Account9Azure Blob Storage10Azure Cache for Redis11Azure Cosmos DB12Azure Database for PostgreSQL/MySQL/MariaDB13Azure Databricks14Azure Files15Azure Synapse Analytics16Batch (Accounts, Pools)17Bot services18CDN profile19Cognitive Services (Azure OpenAI, Computer vision, Content moderator, Language service, Language understanding (classic), Personalizer, Speech service, Translator)20Container instances21Container registries (Container Image)22Compute/Network Usage Limit23Data factories24Dedicated SQL pools25DDoS protection plans26Diagnostic settings27Disks28DNS zones29Event Grid (Topics)30Event Hubs31ExpressRoute circuits32Firewall (Rule, Rule Collection)33Front Doors34Function App35HDInsight clusters36IP Groups37Kubernetes services38Load balancers39Log Analytics workspaces40Logic apps41Management groups42Microsoft Defender for Cloud (Security posture recommendations)43Microsoft Entra ID (Group, Service Principal, User)44NAT gateways45Network interfaces46Network security groups (Flow Logs, Security Rules)47Peerings48Policy (Definitions)49Private Link services50Public IP addresses51Region52Resource groups53Role Definition54Route tables (Route)55Service Bus (Queue)56Service Fabric clusters57Shared Image Gallery (Image Definition, Image Version)58SQL Servers59SSL Certificate60Storage accounts61Storage Sync Services62Subscriptions63Traffic Manager64Virtual machine (Dedicated Host, Image)65Virtual machine scale sets66Virtual network (Private Endpoint, Service Endpoint, Service Endpoint Policy Subnet)67Virtual network gateway