Microsoft Defender for Endpoint streamlined connectivity URLs - US government environments (Preview)
In brief
The page now notes that some device versions still require legacy or expanded URL lists and clarifies that specific client executables, including MsSense.exe and MsMpEng.exe, must be permitted.
What Defender admins need to know
Review the updated URL and process allowlist guidance when configuring Defender for Endpoint connectivity.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Microsoft Defender for Endpoint streamlined connectivity URLs - US government environments (Preview)
Notes
The following notes describe device versions that still require legacy or expanded URL lists.
Devices running Defender for Endpoint delivered via the Microsoft Monitoring Agent (MMA, also known as the Log Analytics Agent - specifically, Windows 7 SP1, Windows 8.1, Windows Server 2008 R2 and those Windows Server 2012 R2, 2016 devices not upgraded to the modern unified solution) will continue using the associated legacy method. For the list of additional URLs, refer to the Windows 7, 8.1, 2008R2 (MMA) tab in Onboard devices using streamlined connectivity for Microsoft Defender for Endpoint.
Devices running Windows version 1607, 1703, 1709, 1803 can onboard using the new onboarding package but still require a longer list of URLs. The Windows 1607 to 1803 tab in Onboard devices using streamlined connectivity for Microsoft Defender for Endpoint lists the additional URLs required.
Client processes that require network connectivity
The following Microsoft Defender for Endpoint client processes generate network communications. Make sure that communications from each of these processes are not blocked. The included list identifies specific executable processes (such as MsSense.exe and MsMpEng.exe) that must be permitted through firewalls and proxies for Defender for Endpoint to function correctly.
[!INCLUDE Microsoft Defender for Endpoint processes]
@@ -11,10 +11,10 @@ ms.collection: - m365-security - tier1 ms.reviewer: pahuijbr-ms.date: 06/16/2026+ms.date: 07/03/2026 appliesto: Microsoft Defender for Endpoint Plan 1, Microsoft Defender for Endpoint Plan 2, Microsoft Defender XDR ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Microsoft Defender for Endpoint streamlined connectivity URLs - US government environments (Preview)@@ -31,6 +31,8 @@ Before using the streamlined connectivity URLs listed in this article, ensure yo ### Notes +The following notes describe device versions that still require legacy or expanded URL lists.+ - Devices running Defender for Endpoint delivered via the Microsoft Monitoring Agent (MMA, also known as the Log Analytics Agent - specifically, Windows 7 SP1, Windows 8.1, Windows Server 2008 R2 and those Windows Server 2012 R2, 2016 devices not upgraded to the modern unified solution) will continue using the associated legacy method. For the list of additional URLs, refer to the Windows 7, 8.1, 2008R2 (MMA) tab in [Onboard devices using streamlined connectivity for Microsoft Defender for Endpoint](configure-device-connectivity.md). - Devices running Windows version 1607, 1703, 1709, 1803 can onboard using the new onboarding package but still require a longer list of URLs. The Windows 1607 to 1803 tab in [Onboard devices using streamlined connectivity for Microsoft Defender for Endpoint](configure-device-connectivity.md) lists the additional URLs required.@@ -121,7 +123,7 @@ The following tables list the required streamlined connectivity endpoints for US <a name="client-processes"></a> ## Client processes that require network connectivity -The following Microsoft Defender for Endpoint client processes generate network communications. Make sure that communications from each of these processes are not blocked.+The following Microsoft Defender for Endpoint client processes generate network communications. Make sure that communications from each of these processes are not blocked. The included list identifies specific executable processes (such as `MsSense.exe` and `MsMpEng.exe`) that must be permitted through firewalls and proxies for Defender for Endpoint to function correctly. [!INCLUDE [Microsoft Defender for Endpoint processes](includes/streamlined-connectivity-processes.md)] 