Step 1: Configure your network environment for connectivity to the Defender for Endpoint service
In brief
The onboarding guidance adds a streamlined-connectivity requirement to bypass inspection for the specified endpoint domain and clarifies proxy and IP-allowlist options.
What Defender admins need to know
Admins using streamlined connectivity should update proxy and network security policies to bypass inspection for the specified endpoint domain.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Step 1: Configure your network environment for connectivity to the Defender for Endpoint service
[!INCLUDE Prerelease information]
Before you onboard devices to Defender for Endpoint, make sure your network is configured to connect to the service,service by allowing outbound connectionconnections and bypassingsbypassing HTTPS inspection for the service URLs. The first step of the device onboarding process involves adding URLs to the allowed domains list if your proxy server or firewall rules prevent access to Defender for Endpoint. This article also includes information about proxy and firewall requirements for older versions of Windows client and Windows Server.
[!INCLUDE Streamlined connectivity SSL inspection requirement]
For devices without Internet access / without a proxy
For devices with no direct internet connection, the use of a proxy solution is the recommended approach. In specific cases,For networks that only permit IP-based allowlists instead of domain-based rules, you can use firewall or gateway devices that allow access to IP ranges. For more information, see: Streamlined device connectivity.
Next steps
Configure your devices to connect to the Defender for Endpoint service using a proxy.
@@ -11,19 +11,21 @@ ms.collection: - tier1 ms.topic: how-to ms.subservice: onboard-ms.date: 06/17/2026+ms.date: 07/28/2026 appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Step 1: Configure your network environment for connectivity to the Defender for Endpoint service [!INCLUDE [Prerelease information](../includes/prerelease.md)] -Before you onboard devices to Defender for Endpoint, make sure your network is configured to connect to the service, by allowing outbound connection and bypassings HTTPS inspection for the service URLs. The first step of the device onboarding process involves adding URLs to the allowed domains list if your proxy server or firewall rules prevent access to Defender for Endpoint. This article also includes information about proxy and firewall requirements for older versions of Windows client and Windows Server.+Before you onboard devices to Defender for Endpoint, make sure your network is configured to connect to the service by allowing outbound connections and bypassing HTTPS inspection for the service URLs. The first step of the device onboarding process involves adding URLs to the allowed domains list if your proxy server or firewall rules prevent access to Defender for Endpoint. This article also includes information about proxy and firewall requirements for older versions of Windows client and Windows Server.++[!INCLUDE [Streamlined connectivity SSL inspection requirement](./includes/streamlined-connectivity-no-ssl-inspection.md)] > [!NOTE] >@@ -44,7 +46,7 @@ The URL lists in the following table specify the services and their associated U > [!IMPORTANT] >-> - Connections are made from the context of the operating system or the Defender client services and as such, proxies shouldn't require authentication for these destinations or perform inspection (HTTPS scanning / SSL inspection) that breaks the secure channel.+> - Connections are made from the context of the operating system or the Defender client services, so proxies shouldn't require authentication for these destinations. For streamlined connectivity, configure your proxy and network security policies to bypass inspection for `*.endpoint.security.microsoft.com` traffic. Don't inspect (HTTPS scanning / SSL inspection), intercept, or man-in-the-middle (MITM) proxy this traffic. > - Microsoft doesn't provide a proxy server. These URLs are accessible via the proxy server that you configure. > - In compliance with Defender for Endpoint security and compliance standards, your data is processed in accordance with your tenant's physical location. Based on client location, traffic may flow through any of the associated IP regions (which correspond to Azure datacenter regions). For more information, see [Data storage and privacy](data-storage-privacy.md). @@ -66,7 +68,7 @@ To determine the exact destinations in use for your subscription within the Log ## For devices without Internet access / without a proxy -For devices with no direct internet connection, the use of a proxy solution is the recommended approach. In specific cases, you can use firewall or gateway devices that allow access to IP ranges. For more information, see: [Streamlined device connectivity](configure-device-connectivity.md).+For devices with no direct internet connection, the use of a proxy solution is the recommended approach. For networks that only permit IP-based allowlists instead of domain-based rules, you can use firewall or gateway devices that allow access to IP ranges. For more information, see: [Streamlined device connectivity](configure-device-connectivity.md). > [!IMPORTANT] >@@ -77,4 +79,4 @@ For devices with no direct internet connection, the use of a proxy solution is t <a name="next-step"></a> ## Next steps -[STEP 2: Configure your devices to connect to the Defender for Endpoint service using a proxy](configure-proxy-internet.md).+[Configure your devices to connect to the Defender for Endpoint service using a proxy](configure-proxy-internet.md). 