Microsoft Defender for Endpoint
Endpoint protection

Microsoft Defender for Endpoint streamlined connectivity URLs - commercial

In brief

The article adds guidance for devices that do not fully support streamlined connectivity, describes URL coverage across scenarios, and clarifies that Defender static IP ranges do not replace access to SmartScreen, Windows Update, or certificate-revocation services.

What Defender admins need to know

Administrators configuring firewalls or proxies can better understand which connectivity requirements remain when using static IP ranges.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Endpoint streamlined connectivity URLs - commercial

[!INCLUDE Microsoft Defender XDR rebranding]

This article includes a list of the streamlined connectivity URLs required to onboard and maintain devices in Microsoft Defender for Endpoint in commercial cloud environments. Use these URLs to configure your network firewall or proxy settings so that devices can communicate with Defender for Endpoint cloud services. Before configuring these URLs, review the streamlined connectivity prerequisites to confirm device eligibility, component versions, and OS requirements.

Prerequisites

Notes

Keep the following considerations in mind for devices that don't fully support the streamlined connectivity model:

  • Devices running Defender for Endpoint delivered via the Microsoft Monitoring Agent (MMA, also known as the Log Analytics Agent) continue to use the associated legacy method. Specifically, devices running on Windows 7 SP1, Windows 8.1, Windows Server 2008 R2, and Windows Server 2012 R2, and 2016 devices not upgraded to the modern unified solution. For the list of additional URLs, see Windows 7, 8.1, 2008R2 (MMA).
  • Devices running Windows version 1607, 1703, 1709, 1803 can onboard using the new onboarding package but still require a longer list of URLs. The Windows 1607 to 1803 section lists the other URLs required.

Common endpoints

The following sections list the endpoint URLs commonly required across scenarios, including core functionality, updates, and certificate validation.

URLs used for core functionality

The following table lists the core endpoint URLs required for Microsoft Defender for Endpoint functionality.

Required IP addresses for streamlined connectivity

The following Defender for Endpoint-dedicated, static IP ranges can be used as an alternative to URLs in certain scenarios without hostname resolution capability.

If you're using Microsoft Defender for Cloud or Intune with the auto from connector option to onboard new devices, ensure to toggle on the Apply streamlined connectivity settings to devices managed by Intune and Defender for Cloud in advanced settings on security.microsoft.com. Onboarded servers don't automatically switch to the new destinations as defined in the Azure service tags. Ensure the servers can connect to the previous standard destinations, or onboard them again to reconfigure them to be able to use the new service tags or IP addresses.

The following table lists the URL endpoints required for administrative and security operations to access the Microsoft Defender security portals. These endpoints don't need to be accessible to all devices.

URL Comment
*.blob.core.windows.net Used for file downloads from the portal, such as onboarding packages - https://onboardingpackagescusprd.blob.core.windows.net and files retrieved from devices.