Microsoft Defender for Endpoint standard connectivity URLs - commercial
In brief
The article’s wording and section labels were revised. The CDN endpoint row is now labeled Mac instead of Common (Mac/Linux), MMA entries use a relative onboard-server.md link, and the Microsoft 365 unified domains note was removed.
What Defender admins need to know
No administrator action is stated. Review the updated endpoint table when validating firewall or proxy allowlists, especially for Mac and MMA connectivity.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Microsoft Defender for Endpoint standard connectivity URLs - commercial
This article includes a list oflists the standard connectivity URLs requiredneeded to onboard and maintain devices in Microsoft Defender for Endpoint in commercial cloud environments. Use this list to configure your networkset up firewall or proxy allow rules so that devices can communicate withreach the required Microsoft Defender for Endpoint services.
Microsoft Defender URLs
The following tableThis section lists the Microsoft Defender service URLs organized by geography and category. Allow these endpoints in your firewall or proxy to ensure proper device connectivity.
| Service | Geography | Category | Port | Endpoint/URL | Endpoint/URL Description | Required or Optional | Windows 10, 11; Server 2022, 2019, 2016 (Unified Agent); Server 2012 R2 (Unified Agent) | Windows 7, 8.1 | Windows Server 2008 R2, 2012 R2, 2016 (MMA Based) | Mac | Linux | Comments |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft Defender for Endpoint | WW | Common | 443 | settings-win.data.microsoft.com |
Connected User Experiences and Telemetry Channel | Optional | Yes | Only required for Windows 10 1703 and below. Not required on Windows Server. | ||||
| Microsoft Defender for Endpoint | WW | Common (Mac/Linux) | 443 | x.cp.wd.microsoft.com |
Used by Microsoft Defender Antivirus to provide cloud-delivered protection and security intelligence updates | Required | Yes | Yes | ||||
| Microsoft Defender for Endpoint | WW | Common (Mac/Linux) | 443 | cdn.x.cp.wd.microsoft.com |
Microsoft Defender Antivirus Content Delivery Network (CDN) - Security Intelligence updates | Required | Yes | Yes | ||||
| Microsoft Defender for Endpoint | WW | 443 | Root URL for public Microsoft CDN endpoints (referred to as ChannelURL) - for the updated URL, see Using Custom channel and ManifestServer to control updates | Microsoft Office Content Delivery Network (CDN) - Product Updates | Required | Yes | New CDN endpoint starting with macOS build 101.26012.0012 | |||||
| Microsoft Defender for Endpoint | WW | Common (Linux) | 443 | packages.microsoft.com |
Required to download and update the MDE Linux agent | Required | Yes | |||||
| Microsoft Defender for Endpoint | WW | Microsoft Defender for Endpoint | 443 | login.windows.net |
Microsoft Defender for Endpoint Vulnerability assessment for network devices (network scanner) | Optional | Yes | Yes | Yes | Supported on Windows 8 and above and Windows Server 2012 and above | ||
| Microsoft Defender for Endpoint | WW | Microsoft Defender for Endpoint | 443 | *.security.microsoft.com |
Microsoft Defender for Endpoint Vulnerability assessment for network devices (network scanner) | Optional | Yes | Yes | Yes | Supported on Windows 8 and above and Windows Server 2012 and above | ||
| Microsoft Defender for Endpoint | WW | Microsoft Defender for Endpoint | 443 | *.blob.core.windows.net/networkscannerstable/* |
Microsoft Defender for Endpoint Vulnerability assessment for network devices (network scanner) | Optional | Yes | Yes | Yes | Supported on Windows 8 and above and Windows Server 2012 and above | ||
| Microsoft Defender for Endpoint | WW | Security Management | 443 | enterpriseregistration.windows.net |
Security Management for Microsoft Defender for Endpoint - Azure Registration | Optional | Yes | Only required when using Security Management for Microsoft Defender for Endpoint | ||||
| Microsoft Defender for Endpoint | WW | Security Management | 443 | *.dm.microsoft.com |
Security Management for Microsoft Defender for Endpoint - Enrollment, check-in, and reporting | Optional | Yes | Only required when using Security Management for Microsoft Defender for Endpoint | ||||
| Microsoft Defender for Endpoint | WW | Microsoft Monitoring Agent (MMA) | 443 | *.ods.opinsights.azure.com |
MMA for Win 7/8.1/2008R2/2012R2/2016 | Optional | Yes | Yes | Required when using MMA. For Windows Server 2012 R2 and 2016, consider migrating to the |
|||
| Microsoft Defender for Endpoint | WW | Microsoft Monitoring Agent (MMA) | 443 | *.oms.opinsights.azure.com |
MMA for Win 7/8.1/2008R2/2012R2/2016 | Optional | Yes | Yes | Required when using MMA. For Windows Server 2012 R2 and 2016, see the |
|||
| Microsoft Defender for Endpoint | WW | Microsoft Monitoring Agent (MMA) | 443 | *.blob.core.windows.net |
MMA for Win 7/8.1/2008R2/2012R2/2016 | Optional | Yes | Yes | Required when using MMA. For Windows Server 2012 R2 and 2016, see the |
|||
| Microsoft Defender for Endpoint | US | Microsoft Defender for Endpoint US | 443 | unitedstates.x.cp.wd.microsoft.com |
Used by Microsoft Defender Antivirus to provide cloud-delivered protection and security intelligence updates | Required | Yes | Yes | ||||
| Microsoft Defender for Endpoint | US | Microsoft Defender for Endpoint US | 443 | us.vortex-win.data.microsoft.com |
Microsoft Defender for Endpoint EDR Cyber Data | Optional | Yes | Not required for Windows 10 1803 (RS4) and above / Windows Server 2019 and above | ||||
| Microsoft Defender for Endpoint | US | Microsoft Defender for Endpoint US | 443 | us-v20.events.data.microsoft.com |
Microsoft Defender for Endpoint EDR Cyber Data | Required | Yes | Yes | Yes |
Defender portal URLs
The following tableThis section lists the URLs requiredneeded to accessopen the Microsoft Defender portal fromin a browser.
| Service | Geography | URL | ||||||
|---|---|---|---|---|---|---|---|---|
Required client processes for network connectivityBecause the Microsoft Defender for Endpoint client processes [!INCLUDE Microsoft Defender for Endpoint processes] Changelog
|
