Defender for Endpoint (streamlined)
Streamlined device connectivity for Microsoft Defender for Endpoint on Windows, with the update, certificate validation, SmartScreen and Live Response hosts.
Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Defender
Do not TLS-inspect *.endpoint.security.microsoft.com or require proxy authentication for it. Update hosts are optional when updates come from WSUS, a file share or Configuration Manager. Linux-only, network scanner and portal URLs are left out; portal addresses are in m365-admin. The downloadable streamlined URL spreadsheet has been replaced by the Learn page.
Cited pages since the review
2 of 2 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint data| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 21 | 0 | Open |
| GSA V1 domain list | 18 | 3 | Open |
| GSA V1 Graph request body | 21 | 0 | Download |
| GSA V2 rules (review JSON) | 21 | 0 | Download |
| GSA V2 rules (CSV) | 21 | 0 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/defender-endpoint. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle defender-endpoint from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Not determined20public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
crl. |
TCP 80 | Certificate revocation lists for certificate validationWindows. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 84Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ctldl. |
TCP 80 | Automatic root update / certificate trust list; flags compromised certificates as untrustedDisconnected devices must update CTLs offline instead (configure-environment, 'Connect devices without direct internet access'). | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
definitionupdates. |
TCP 443 | Defender Antivirus security intelligence and platform update CDNOptional if updates are distributed centrally. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Windows Update delivery for Defender updatesWindows; optional with central update distribution. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Microsoft download CDN for Defender updatesWindows; optional with central update distribution. EDR sensor updates ship with Windows Update; KB5005292 for 2012 R2/2016. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Windows Update download for Defender updatesWindows; optional with central update distribution. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Consolidated core MDE services: cloud-delivered protection (MAPS), sample submission and AutoIR storage, command and control, cyber/diagnostic dataPort 443 comes from the streamlined commercial list (URLs used for core functionality). Exclude from TLS/SSL inspection and MITM: the service uses certificate pinning, and enforcing proxy user authentication breaks it. configure-environment says devices need it even on standard connectivity. IP-only alternative: service tags MicrosoftDefenderForEndpoint plus OneDsCollector (both needed). | PublishedOnboard devices using streamlined connectivity for Microsoft Defender for EndpointMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
go. |
TCP 443 | Defender Antivirus CDN: security intelligence and platform updates (MMPC alternative/fallback)Required; optional if updates are distributed centrally (WSUS, mirror, ConfigMgr). | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 89Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
https:/ |
TCP 443 | Defender Antivirus update package location (MMPC)Optional if updates are distributed centrally. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | SmartScreen browsing protection, network/web protection, web content filtering, custom URL/IP indicatorsType Required. Optional in disconnected environments; required for custom URL/IP indicators. All OSes. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | SmartScreen web/network protection and app-execution reputationListed in two rows: 'Web & network protection' (Required) and 'SmartScreen' (Optional, Windows). | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Windows Update source for security intelligence, platform and EDR sensor updatesWindows; optional with WSUS/mirror/ConfigMgr. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Windows Update delivery for Defender updatesWindows; optional with central update distribution. Listed on 443; ctldl.windowsupdate.com is listed separately on port 80. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80 | Certificate revocation list updates (Windows certificate validation)Published without a scheme; port 80. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80 | Certificate revocation list updates used when creating the SSL connection to MAPSPublished without a scheme; port 80 means plain HTTP. Optional if root trust lists are managed another way. If cloud protection can't reach it through a proxy, the page says to set SSLOptions=0 under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | SmartScreen check of application execution for trusted appsOptional; Windows; reputation of downloaded apps. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
login.optional |
TCP 443 | Live Response push notification modelOptional; Windows client. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 97Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
reflector.optional |
TCP 443 | Defender IPv6 connectivity probeOptional; all OSes; added 06/02/2026. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | SmartScreen application reputationOptional; Windows. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Windows Push Notification Services for Live ResponseOptional; the page says WNS can't be used through a proxy. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 35Microsoft traffic profile · possible, not confirmedIn Microsoft 365 SharePoint endpoint set 35 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
Probably taken before Internet Access1public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
login.optional |
TCP 443 | Live Response push notifications (WNS) and Entra sign-in to the Defender portalOptional for devices (Live Response push model; needs direct connection or proxy bypass on Windows client OS). Also listed under 'Defender portal URLs' as https://login.microsoftonline.com for admin sign-in. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |