Microsoft Defender for Endpoint
Endpoint protection

Step 1: Configure your network environment for connectivity to the Defender for Endpoint service

In brief

The onboarding guidance adds a streamlined-connectivity requirement to bypass inspection for the specified endpoint domain and clarifies proxy and IP-allowlist options.

What Defender admins need to know

Admins using streamlined connectivity should update proxy and network security policies to bypass inspection for the specified endpoint domain.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Step 1: Configure your network environment for connectivity to the Defender for Endpoint service

[!INCLUDE Prerelease information]

Before you onboard devices to Defender for Endpoint, make sure your network is configured to connect to the service,service by allowing outbound connectionconnections and bypassingsbypassing HTTPS inspection for the service URLs. The first step of the device onboarding process involves adding URLs to the allowed domains list if your proxy server or firewall rules prevent access to Defender for Endpoint. This article also includes information about proxy and firewall requirements for older versions of Windows client and Windows Server.

[!INCLUDE Streamlined connectivity SSL inspection requirement]

For devices without Internet access / without a proxy

For devices with no direct internet connection, the use of a proxy solution is the recommended approach. In specific cases,For networks that only permit IP-based allowlists instead of domain-based rules, you can use firewall or gateway devices that allow access to IP ranges. For more information, see: Streamlined device connectivity.

Next steps

Configure your devices to connect to the Defender for Endpoint service using a proxy.