Microsoft Defender for Endpoint
Endpoint protection

Onboarding devices using streamlined connectivity for Microsoft Defender for Endpoint

In brief

The article now explicitly lists the simplified Defender for Endpoint domains, clarifies OneDsCollector URL-level consolidation, and updates links to Azure service tags and the client analyzer.

What Defender admins need to know

Administrators can use the clearer domain guidance and updated references when configuring or validating device connectivity. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Onboarding devices using streamlined connectivity for Microsoft Defender for Endpoint

Once you confirm prerequisites are met, ensure your network environment is properly configured to support the streamlined connectivity method. Follow the steps outlined in Configure your network environment to ensure connectivity with Defender for Endpoint service.

Defender for Endpoint service URLs consolidated under the simplified domain (*.endpoint.security.microsoft.com or *.endpoint.security.microsoft.us) should no longer be required for connectivity. However, some Defender for Endpoint service URLs aren't included in the simplified-domain consolidation.

Streamlined connectivity allows you to use the following option to configure cloud connectivity:

  • Defender for Endpoint Command and Control

In order to stay up to date on IP ranges, it's recommended to refer to the following Azure service tags for Microsoft Defender for Endpoint services. The latest IP ranges are found in the service tag. For more information, see Azure IP ranges.

| MicrosoftDefenderForEndpoint | Cloud-delivered protection, malware sample submission storage, Auto-IR sample storage, Defender for Endpoint command and control. | | OneDsCollector | Defender for Endpoint cyber and diagnostic data

Note: The traffic under this service tag isn't limited to Defender for Endpoint and can include diagnostic data traffic for other Microsoft services. |

For the latest list of Azure service tags, including the Defender for Endpoint-related tags list,listed in the preceding table, refer to the Azure service tags documentation.

  • Run mdeclientanalyzer.cmd -g <GW_US, GW_UK, GW_EU> , where parameter is of GW_US, GW_EU, GW_UK. GW refers to the streamlined option. Run with applicable tenant geo.

As a supplementary check, you can also use the client analyzer to test whether a device meets prerequisites: Download the Microsoft Defender for Endpoint client analyzer preview.