Microsoft Defender for Endpoint
Endpoint protection

Microsoft Defender for Endpoint standard connectivity URLs - commercial

In brief

The article’s wording and section labels were revised. The CDN endpoint row is now labeled Mac instead of Common (Mac/Linux), MMA entries use a relative onboard-server.md link, and the Microsoft 365 unified domains note was removed.

What Defender admins need to know

No administrator action is stated. Review the updated endpoint table when validating firewall or proxy allowlists, especially for Mac and MMA connectivity.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Endpoint standard connectivity URLs - commercial

This article includes a list oflists the standard connectivity URLs requiredneeded to onboard and maintain devices in Microsoft Defender for Endpoint in commercial cloud environments. Use this list to configure your networkset up firewall or proxy allow rules so that devices can communicate withreach the required Microsoft Defender for Endpoint services.

Microsoft Defender URLs

The following tableThis section lists the Microsoft Defender service URLs organized by geography and category. Allow these endpoints in your firewall or proxy to ensure proper device connectivity.

Service Geography Category Port Endpoint/URL Endpoint/URL Description Required or Optional Windows 10, 11; Server 2022, 2019, 2016 (Unified Agent); Server 2012 R2 (Unified Agent) Windows 7, 8.1 Windows Server 2008 R2, 2012 R2, 2016 (MMA Based) Mac Linux Comments
Microsoft Defender for Endpoint WW Common 443 settings-win.data.microsoft.com Connected User Experiences and Telemetry Channel Optional Yes Only required for Windows 10 1703 and below. Not required on Windows Server.
Microsoft Defender for Endpoint WW Common (Mac/Linux) 443 x.cp.wd.microsoft.com Used by Microsoft Defender Antivirus to provide cloud-delivered protection and security intelligence updates Required Yes Yes
Microsoft Defender for Endpoint WW Common (Mac/Linux) 443 cdn.x.cp.wd.microsoft.com Microsoft Defender Antivirus Content Delivery Network (CDN) - Security Intelligence updates Required Yes Yes
Microsoft Defender for Endpoint WW Common (Mac/Linux)Mac 443 Root URL for public Microsoft CDN endpoints (referred to as ChannelURL) - for the updated URL, see Using Custom channel and ManifestServer to control updates Microsoft Office Content Delivery Network (CDN) - Product Updates Required Yes Yes New CDN endpoint starting with macOS build 101.26012.0012
Microsoft Defender for Endpoint WW Common (Linux) 443 packages.microsoft.com Required to download and update the MDE Linux agent Required Yes
Microsoft Defender for Endpoint WW Microsoft Defender for Endpoint 443 login.windows.net Microsoft Defender for Endpoint Vulnerability assessment for network devices (network scanner) Optional Yes Yes Yes Supported on Windows 8 and above and Windows Server 2012 and above
Microsoft Defender for Endpoint WW Microsoft Defender for Endpoint 443 *.security.microsoft.com Microsoft Defender for Endpoint Vulnerability assessment for network devices (network scanner) Optional Yes Yes Yes Supported on Windows 8 and above and Windows Server 2012 and above
Microsoft Defender for Endpoint WW Microsoft Defender for Endpoint 443 *.blob.core.windows.net/networkscannerstable/* Microsoft Defender for Endpoint Vulnerability assessment for network devices (network scanner) Optional Yes Yes Yes Supported on Windows 8 and above and Windows Server 2012 and above
Microsoft Defender for Endpoint WW Security Management 443 enterpriseregistration.windows.net Security Management for Microsoft Defender for Endpoint - Azure Registration Optional Yes Only required when using Security Management for Microsoft Defender for Endpoint
Microsoft Defender for Endpoint WW Security Management 443 *.dm.microsoft.com Security Management for Microsoft Defender for Endpoint - Enrollment, check-in, and reporting Optional Yes Only required when using Security Management for Microsoft Defender for Endpoint
Microsoft Defender for Endpoint WW Microsoft Monitoring Agent (MMA) 443 *.ods.opinsights.azure.com MMA for Win 7/8.1/2008R2/2012R2/2016 Optional Yes Yes Required when using MMA. For Windows Server 2012 R2 and 2016, consider migrating to the Microsoft Defender for Endpoint unified agentMicrosoft Defender for Endpoint unified agent. Refer to steps at https://aka.ms/mde_network_requirements to eliminate wildcards (*)
Microsoft Defender for Endpoint WW Microsoft Monitoring Agent (MMA) 443 *.oms.opinsights.azure.com MMA for Win 7/8.1/2008R2/2012R2/2016 Optional Yes Yes Required when using MMA. For Windows Server 2012 R2 and 2016, see the Microsoft Defender for Endpoint unified agentMicrosoft Defender for Endpoint unified agent. Refer to steps at https://aka.ms/mde_network_requirements to eliminate wildcards (*)
Microsoft Defender for Endpoint WW Microsoft Monitoring Agent (MMA) 443 *.blob.core.windows.net MMA for Win 7/8.1/2008R2/2012R2/2016 Optional Yes Yes Required when using MMA. For Windows Server 2012 R2 and 2016, see the Microsoft Defender for Endpoint unified agentMicrosoft Defender for Endpoint unified agent. Refer to steps at https://aka.ms/mde_network_requirements to eliminate wildcards (*)
Microsoft Defender for Endpoint US Microsoft Defender for Endpoint US 443 unitedstates.x.cp.wd.microsoft.com Used by Microsoft Defender Antivirus to provide cloud-delivered protection and security intelligence updates Required Yes Yes
Microsoft Defender for Endpoint US Microsoft Defender for Endpoint US 443 us.vortex-win.data.microsoft.com Microsoft Defender for Endpoint EDR Cyber Data Optional Yes Not required for Windows 10 1803 (RS4) and above / Windows Server 2019 and above
Microsoft Defender for Endpoint US Microsoft Defender for Endpoint US 443 us-v20.events.data.microsoft.com Microsoft Defender for Endpoint EDR Cyber Data Required Yes Yes Yes

Defender portal URLs

The following tableThis section lists the URLs requiredneeded to accessopen the Microsoft Defender portal fromin a browser.

Service Geography URL
.
ServiceGeographyURL

Required client processes for network connectivity

Because the Microsoft Defender for Endpoint client processes listed belowin this section generate network communications, make sure that traffic from those processes is not blocked.

[!INCLUDE Microsoft Defender for Endpoint processes]

Changelog

The following tableThis section summarizes recent changes to this article and its endpoint listings.

Date Change Log