Microsoft Defender for Endpoint
Endpoint protection

Microsoft Defender for Endpoint streamlined connectivity URLs - US government environments (Preview)

In brief

The page now notes that some device versions still require legacy or expanded URL lists and clarifies that specific client executables, including MsSense.exe and MsMpEng.exe, must be permitted.

What Defender admins need to know

Review the updated URL and process allowlist guidance when configuring Defender for Endpoint connectivity.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Endpoint streamlined connectivity URLs - US government environments (Preview)

Notes

The following notes describe device versions that still require legacy or expanded URL lists.

Client processes that require network connectivity

The following Microsoft Defender for Endpoint client processes generate network communications. Make sure that communications from each of these processes are not blocked. The included list identifies specific executable processes (such as MsSense.exe and MsMpEng.exe) that must be permitted through firewalls and proxies for Defender for Endpoint to function correctly.

[!INCLUDE Microsoft Defender for Endpoint processes]