182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Defender for Endpoint (streamlined)

Streamlined device connectivity for Microsoft Defender for Endpoint on Windows, with the update, certificate validation, SmartScreen and Live Response hosts.

Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Defender

Do not TLS-inspect *.endpoint.security.microsoft.com or require proxy authentication for it. Update hosts are optional when updates come from WSUS, a file share or Configuration Manager. Linux-only, network scanner and portal URLs are left out; portal addresses are in m365-admin. The downloadable streamlined URL spreadsheet has been replaced by the Learn page.

Cited pages since the review

2 of 2 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data
FormatDestinationsLeft outDownload
Plain list, one per line210 Open
GSA V1 domain list183 Open
GSA V1 Graph request body210 Download
GSA V2 rules (review JSON)210 Download
GSA V2 rules (CSV)210 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/defender-endpoint. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle defender-endpoint from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Not determined20public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
crl.microsoft.com TCP 80 Certificate revocation lists for certificate validationWindows. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 84
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

ctldl.windowsupdate.com TCP 80 Automatic root update / certificate trust list; flags compromised certificates as untrustedDisconnected devices must update CTLs offline instead (configure-environment, 'Connect devices without direct internet access'). PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

definitionupdates.microsoft.com TCP 443 Defender Antivirus security intelligence and platform update CDNOptional if updates are distributed centrally. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.delivery.mp.microsoft.com TCP 443 Windows Update delivery for Defender updatesWindows; optional with central update distribution. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.download.microsoft.com TCP 443 Microsoft download CDN for Defender updatesWindows; optional with central update distribution. EDR sensor updates ship with Windows Update; KB5005292 for 2012 R2/2016. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.download.windowsupdate.com TCP 443 Windows Update download for Defender updatesWindows; optional with central update distribution. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.endpoint.security.microsoft.com TCP 443 Consolidated core MDE services: cloud-delivered protection (MAPS), sample submission and AutoIR storage, command and control, cyber/diagnostic dataPort 443 comes from the streamlined commercial list (URLs used for core functionality). Exclude from TLS/SSL inspection and MITM: the service uses certificate pinning, and enforcing proxy user authentication breaks it. configure-environment says devices need it even on standard connectivity. IP-only alternative: service tags MicrosoftDefenderForEndpoint plus OneDsCollector (both needed). PublishedOnboard devices using streamlined connectivity for Microsoft Defender for Endpoint
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

go.microsoft.com TCP 443 Defender Antivirus CDN: security intelligence and platform updates (MMPC alternative/fallback)Required; optional if updates are distributed centrally (WSUS, mirror, ConfigMgr). PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 89
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

https://www.microsoft.com/security/encyclopedia/adlpackages.aspx TCP 443 Defender Antivirus update package location (MMPC)Optional if updates are distributed centrally. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.smartscreen-prod.microsoft.com TCP 443 SmartScreen browsing protection, network/web protection, web content filtering, custom URL/IP indicatorsType Required. Optional in disconnected environments; required for custom URL/IP indicators. All OSes. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.smartscreen.microsoft.com TCP 443 SmartScreen web/network protection and app-execution reputationListed in two rows: 'Web & network protection' (Required) and 'SmartScreen' (Optional, Windows). PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.update.microsoft.com TCP 443 Windows Update source for security intelligence, platform and EDR sensor updatesWindows; optional with WSUS/mirror/ConfigMgr. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.windowsupdate.com TCP 443 Windows Update delivery for Defender updatesWindows; optional with central update distribution. Listed on 443; ctldl.windowsupdate.com is listed separately on port 80. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

www.microsoft.com/pki/* TCP 80 Certificate revocation list updates (Windows certificate validation)Published without a scheme; port 80. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

www.microsoft.com/pkiops/* TCP 80 Certificate revocation list updates used when creating the SSL connection to MAPSPublished without a scheme; port 80 means plain HTTP. Optional if root trust lists are managed another way. If cloud protection can't reach it through a proxy, the page says to set SSLOptions=0 under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.checkappexec.microsoft.comoptional TCP 443 SmartScreen check of application execution for trusted appsOptional; Windows; reputation of downloaded apps. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

login.live.comoptional TCP 443 Live Response push notification modelOptional; Windows client. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 97
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

reflector.defender.microsoft.comoptional TCP 443 Defender IPv6 connectivity probeOptional; all OSes; added 06/02/2026. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.urs.microsoft.comoptional TCP 443 SmartScreen application reputationOptional; Windows. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.wns.windows.comoptional TCP 443 Windows Push Notification Services for Live ResponseOptional; the page says WNS can't be used through a proxy. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 35
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 SharePoint endpoint set 35 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access1public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
login.microsoftonline.comoptional TCP 443 Live Response push notifications (WNS) and Entra sign-in to the Defender portalOptional for devices (Live Response push model; needs direct connection or proxy bypass on Windows client OS). Also listed under 'Defender portal URLs' as https://login.microsoftonline.com for admin sign-in. PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercial · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current