Azure for AWS professionals
This series of articles helps Amazon Web Services (AWS) experts understand the basics of Microsoft Azure accounts, platform, and services. These articles also cover key similarities and differences between AWS and Azure. Whether you are planning a multicloud solution with Azure and AWS or migrating to Azure, you can compare the capabilities of Azure and AWS services in all categories.
These articles describe:
- How Azure organizes accounts and resources.
- How Azure structures available solutions.
- How the major Azure services differ from AWS services or how they are similar.
Use the table of contents to select specific technology areas that are relevant to your workload. These articles compare services that are roughly comparable. Not every AWS service or Azure service is listed, and not every matched service has exact feature-for-feature parity.
Similarities and differences
Like AWS, Microsoft Azure builds on a core set of compute, storage, database, and networking services. In many cases, the platforms offer similar products and services. For example, both AWS and Azure can use Linux distributions and open-source software technologies. Both platforms support building highly available solutions on Windows or Linux hosts.
While the capabilities of both platforms are similar, the resources that provide those capabilities are often organized differently. Azure and AWS built their capabilities independently over time, so the platforms have important implementation and design differences. Exact one-to-one correspondences between the services that you need to build a solution aren't always clear. Sometimes, only one of the platforms offers a particular service.
Not all Azure products and services are available in all regions. For details, see Products available by region. For Azure product and service uptime guarantees and downtime credit policies, see Service Level Agreements (SLA) for Online Services.
Primary topics
Use the following pages to learn about Azure technologies and how they map to technologies you are already familre with in Amazon Web Services (AWS). These articles go into a bit more details on how Azure works in these specific areas
- Azure and AWS accounts and subscriptions
- Compute services on Azure and AWS
- Data and AI
- Relational database technologies on Azure and AWS
- Messaging services on Azure and AWS
- Networking on Azure and AWS
- Regions and zones on Azure and AWS
- Resource management on Azure and AWS
- Multicloud security and identity with Azure and AWS
- Compare storage on Azure and AWS
Additional categories
There are some services not covered in the prior articles. Those services are mapped here from their AWS service to their matching Azure service.
Marketplace
AWS service | Azure service | Description |
---|---|---|
AWS Marketplace | Azure Marketplace | Easy-to-deploy and automatically configured third-party applications, including single virtual machine or multiple virtual machine solutions. |
AI and machine learning
AWS service | Azure service | Description |
---|---|---|
Alexa Skills Kit | Bot Framework | Build and connect intelligent bots that interact with your users using text/SMS, Skype, Teams, Slack, Microsoft 365 mail, Twitter, and other popular services. |
Skills Kit | Virtual Assistant | The Virtual Assistant Template brings together a number of best practices we've identified through the building of conversational experiences and automates integration of components that we've found to be highly beneficial to Bot Framework developers. |
Time series databases and analytics
AWS service | Azure service | Description |
---|---|---|
Amazon Timestream | Azure Data Explorer Azure Time Series Insights |
Fully managed, low latency, and distributed big data analytics platform that runs complex queries across petabytes of data. Highly optimized for log and time series data. Open and scalable end-to-end IoT analytics service. Collect, process, store, query, and visualize data at Internet of Things (IoT) scale--data that's highly contextualized and optimized for time series. |
Analytics and visualization
AWS service | Azure service | Description |
---|---|---|
Elasticsearch Service | Elastic on Azure | Use the Elastic Stack (Elastic, Logstash, and Kibana) to search, analyze, and visualize in real time. |
DevOps and application monitoring
AWS service | Azure service | Description |
---|---|---|
CloudWatch, X-Ray | Azure Monitor | Comprehensive solution for collecting, analyzing, and acting on telemetry from your cloud and on-premises environments. |
CodeDeploy CodeCommit CodePipeline |
DevOps | A cloud service for collaborating on code development. |
Developer Tools | Developer Tools | Collection of tools for building, debugging, deploying, diagnosing, and managing multiplatform scalable apps and services. |
CodeBuild | DevOps Pipeline GitHub Actions |
Fully managed build service that supports continuous integration and continuous deployment (CI/CD). |
Command-line interface | CLI PowerShell |
Built on top of the native REST API across all cloud services, various programming language-specific wrappers provide easier ways to create solutions. |
eksctl |
az aks command group |
Manage Azure Kubernetes Service (AKS) using these Azure CLI commands. |
AWS CloudShell | Azure Cloud Shell | Azure Cloud Shell is an interactive, authenticated, browser-accessible shell for managing Azure resources. It gives you the flexibility to choose the shell experience that best suits the way you work, either Bash or PowerShell. |
OpsWorks (Chef-based) | Automation | Configures and operates applications of all shapes and sizes, and provides templates to create and manage a collection of resources. |
CloudFormation | Resource Manager Bicep VM extensions Azure Automation |
Provides a way for users to automate the manual, long-running, error-prone, and frequently repeated IT tasks. |
Cloud Development Kit | Azure Developer CLI Azure Verified Modules |
Developer-friendly imperative commands that enable consistent and repeatable work and standardized infrastructure-as-code modules. |
Internet of Things (IoT)
AWS service | Azure service | Description |
---|---|---|
IoT Core | IoT Hub | A cloud gateway for managing bidirectional communication with billions of IoT devices, securely and at scale. |
Greengrass | IoT Edge | Deploy cloud intelligence directly onto IoT devices, catering to on-premises scenarios. |
Kinesis Firehose, Kinesis Streams | Event Hubs | Services that facilitate the mass ingestion of events (messages), typically from devices and sensors. The data can then be processed in real-time micro-batches or be written to storage for further analysis. |
IoT Things Graph | Digital Twins | Services you can use to create digital representations of real-world things, places, business processes, and people. Use these services to gain insights, drive the creation of better products and new customer experiences, and optimize operations and costs. |
Management and governance
AWS service | Azure service | Description |
---|---|---|
AWS Organizations | Management Groups | Azure management groups help you organize your resources and subscriptions. |
AWS Well-Architected Tool | Azure Well-Architected Review | Examine your workload through the lenses of reliability, cost management, operational excellence, security, and performance efficiency. |
Trusted Advisor | Azure Advisor | Provides analysis of cloud resource configuration and security, so that subscribers can ensure they're making use of best practices and optimum configurations. |
AWS Billing and Cost Management | Microsoft Cost Management | Microsoft Cost Management helps you understand your Azure invoice (bill), manage your billing account and subscriptions, monitor and control Azure spending, and optimize resource use. |
Cost and Usage Reports | Usage Details API | Services to help generate, monitor, forecast, and share billing data for resource usage by time, organization, or product resources. |
Management Console | Portal | A unified management console that simplifies building, deploying, and operating your cloud resources. |
Application Discovery Service | Migrate | Assesses on-premises workloads for migration to Azure, performs performance-based sizing, and provides cost estimations. |
Systems Manager | Monitor | Comprehensive solution for collecting, analyzing, and acting on telemetry from your cloud and on-premises environments. |
Personal Health Dashboard | Resource Health | Provides detailed information about the health of resources, as well as recommended actions for maintaining resource health. |
CloudTrail | Activity log | The Activity log is a platform log in Azure that provides insight into subscription-level events, such as when a resource is modified or when a virtual machine is started. |
CloudWatch | Application Insights | A feature of Azure Monitor, Application Insights is an extensible Application Performance Management (APM) service for developers and DevOps professionals, which provides telemetry insights and information, in order to better understand how applications are performing and to identify areas for optimization. |
Config | Application Change Analysis | Application Change Analysis detects various types of changes, from the infrastructure layer all the way to application deployment. |
Cost Explorer | Cost Management | Optimize costs while maximizing cloud potential. |
Control Tower | Azure Lighthouse | Set up and govern a multi account/subscription environment. |
Resource Groups and Tag Editor | Resource Groups and Tags | A Resource Group is a container that holds related resources for an Azure solution. Apply tags to your Azure resources to logically organize them by categories. |
AWS AppConfig | Azure App Configuration | Azure App Configuration is a managed service that helps developers centralize their application and feature settings simply and securely. |
Service Catalog | Azure Managed Applications | Offers cloud solutions that are easy for consumers to deploy and operate. |
SDKs and tools | SDKs and tools | Manage and interact with Azure services the way you prefer, programmatically from your language of choice, by using the Azure SDKs, our collection of tools, or both. |
Authentication and authorization
AWS service | Azure service | Description |
---|---|---|
Identity and Access Management (IAM) | Microsoft Entra ID | Allows users to securely control access to services and resources while offering data security and protection. Create and manage users and groups, and use permissions to allow and deny access to resources. |
Identity and Access Management (IAM) | Azure role-based access control (RBAC) | Azure role-based access control (RBAC) helps you manage who has access to Azure resources, what they can do with those resources, and what areas they have access to. |
Organizations | Subscription Management + Azure RBAC | Security policy and role management for working with multiple accounts. |
Multi-Factor Authentication | Microsoft Entra ID | Safeguard access to data and applications while meeting user demand for a simple sign-in process. |
Directory Service | Microsoft Entra Domain Services | Provides managed domain services, such as domain join, group policy, LDAP, and Kerberos/NTLM authentication, which are fully compatible with Windows Server Active Directory. |
Cognito | Microsoft Entra External ID | A highly available, global identity management service for consumer-facing applications that scales to hundreds of millions of identities. |
AWS Config | Policy | Azure Policy is a service in Azure that you use to create, assign, and manage policies. These policies enforce different rules and effects over your resources so those resources stay compliant with your corporate standards and service-level agreements. |
Organizations | Management Groups | Azure management groups provide a level of scope above subscriptions. You organize subscriptions into containers called "management groups" and apply your governance conditions to the management groups. All subscriptions within a management group automatically inherit the conditions applied to the management group. Management groups give you enterprise-grade management at a large scale, no matter what type of subscriptions you have. |
Encryption
AWS service | Azure service | Description |
---|---|---|
Server-side encryption with Amazon S3 Key Management Service | Azure Storage Service Encryption | Helps you protect and safeguard your data and meet your organizational security and compliance commitments. |
Key Management Service (KMS), CloudHSM | Key Vault | Provides security solution and works with other services by providing a way to manage, create, and control encryption keys stored in hardware security modules (HSMs). |
Firewalls
AWS service | Azure service | Description |
---|---|---|
Web Application Firewall | Web Application Firewall | A firewall that protects web applications from common web exploits. |
AWS Network Firewall | Firewall | Provides inbound protection for non-HTTP/S protocols, outbound network-level protection for all ports and protocols, and application-level protection for outbound HTTP/S. |
Security
AWS service | Azure service | Description |
---|---|---|
Inspector | Defender for Cloud | An automated security assessment service that improves the security and compliance of applications. Automatically assess applications for vulnerabilities or deviations from best practices. |
Certificate Manager | App Service Certificates available on the Portal | Service that allows customers to create, manage, and consume certificates seamlessly in the cloud. |
GuardDuty | Microsoft Sentinel | Detect and investigate advanced attacks on-premises and in the cloud. |
Artifact | Service Trust Portal | Provides access to audit reports, compliance guides, and trust documents from across cloud services. |
Shield | DDoS Protection Service | Provides cloud services with protection from distributed denial of services (DDoS) attacks. |
Web applications
AWS service | Azure service | Description |
---|---|---|
Elastic Beanstalk | App Service | Managed hosting platform providing easy to use services for deploying and scaling web applications and services. |
API Gateway | API Management | A turnkey solution for publishing APIs to external and internal consumers. |
CloudFront | Azure Front Door | Azure Front Door is a modern cloud content delivery network (CDN) service that delivers high performance, scalability, and secure user experiences for your content and applications. |
Global Accelerator | Azure Front Door | Easily join your distributed microservices architectures into a single global application using HTTP load balancing and path-based routing rules. Automate turning up new regions and scale-out with API-driven global actions and independent fault-tolerance to your back-end microservices in Azure or anywhere. |
Global Accelerator | Cross-regional load balancer | Distribute and load balance traffic across multiple Azure regions via a single, static, global anycast public IP address. |
Lightsail | App Service | Build, deploy, and scale web apps on a fully managed platform. |
App Runner | Web App for Containers | Easily deploy and run containerized web apps on Windows and Linux. |
Amplify | Static Web Apps | Boost productivity with a tailored developer experience, CI/CD workflows to build and deploy your static content hosting, and dynamic scale for integrated serverless APIs. |
End-user computing
AWS service | Azure service | Description |
---|---|---|
WorkSpaces, AppStream 2.0 | Azure Virtual Desktop | Manage virtual desktops and applications to enable corporate network and data access to users, anytime, anywhere, from supported devices. Amazon WorkSpaces support Windows and Linux virtual desktops. Azure Virtual Desktop supports multi-session Windows 10 virtual desktops. |
WorkLink | Application Proxy | Provides access to intranet applications without requiring VPN connectivity. Amazon WorkLink is limited to iOS and Android devices. |
Miscellaneous
Area | AWS service | Azure service | Description |
---|---|---|---|
Backend process logic | Step Functions | Logic Apps | Cloud technology to build distributed applications using out-of-the-box connectors to reduce integration challenges. Connect apps, data, and devices on-premises or in the cloud. |
Enterprise application services | WorkMail, WorkDocs, Chime | Microsoft 365 | Fully integrated cloud service that provides communications, email, and document management in the cloud and is available on a wide variety of devices. |
Gaming | GameLift | PlayFab | Managed services for hosting dedicated game servers. |
Media transcoding | Elastic Transcoder | Media Services | Services that offer broadcast-quality video streaming services, including various transcoding technologies. |
Workflow | Step Functions | Logic Apps | Serverless technology for connecting apps, data and devices anywhere, whether on-premises or in the cloud for large ecosystems of SaaS and cloud-based connectors. |
Hybrid | Outposts | Stack | Azure Stack is a hybrid cloud platform that enables you to run Azure services in your company's or service provider's datacenter. As a developer, you can build apps on Azure Stack. You can then deploy them to either Azure Stack or Azure, or you can build truly hybrid apps that take advantage of connectivity between an Azure Stack cloud and Azure. |
Media | Elemental MediaConvert | Media Services | Cloud-based media workflow platform to index, package, protect, and stream video at scale. |
Satellite | Ground Station | Azure Orbital | Fully managed cloud-based ground station as a service. |
Quantum computing | Amazon Braket | Azure Quantum | Managed quantum computing service that developers, researchers, and businesses can use to run quantum computing programs. |