Azure Arc and Defender for Endpoint Ports & URLs

Security, Microsoft 36508/02/2022

During the onboarding / rollout of Defender for Endpoint and Azure Arc Agent, the network plays a significant role. Communication via the Internet is usually restricted by segmented networks and secured by firewalls and proxies. To prevent errors or communication problems, the required ports & URLs should be opened to ensure seamless onboarding and operational processes.

For this purpose, I have collected the relevant ports and URLs for Defender for Endpoint, Microsoft Defender Antivirus, Azure Arc Agent, Microsoft Defender SmartScreen, Azure Monitor Agent in the table below.

UsageRegionSubcategoryPortUrl
Microsoft Defender for EndpointWWCRL80crl.microsoft.com
Microsoft Defender for EndpointWWCRL80ctldl.windowsupdate.com
Microsoft Defender for EndpointWWCRL80www.microsoft.com/pkiops/*
Microsoft Defender for EndpointWWCRL80www.microsoft.com/pki/*
Microsoft Defender for EndpointWWCommon443events.data.microsoft.com
Microsoft Defender for EndpointWWCommon443*.wns.windows.com
Microsoft Defender for EndpointWWCommon443login.microsoftonline.com
Microsoft Defender for EndpointWWCommon443login.live.com
Microsoft Defender for EndpointWWCommon443settings-win.data.microsoft.com
Microsoft Defender for EndpointWWCommon (Mac/Linux)443x.cp.wd.microsoft.com
Microsoft Defender for EndpointWWCommon (Mac/Linux)443cdn.x.cp.wd.microsoft.com
Microsoft Defender for EndpointWWCommon (Mac/Linux)443officecdn-microsoft-com.akamaized.net
Microsoft Defender for EndpointWWCommon (Linux)443packages.microsoft.com
Microsoft Defender for EndpointWWMicrosoft Defender for Endpoint443login.windows.net
Microsoft Defender for EndpointWWMicrosoft Defender for Endpoint443*.security.microsoft.com
Microsoft Defender for EndpointWWMicrosoft Defender for Endpoint443.blob.core.windows.net/networkscannerstable/
Microsoft Defender for EndpointWWSecurity Management443enterpriseregistration.windows.net
Microsoft Defender for EndpointWWSecurity Management443*.dm.microsoft.com
Microsoft Defender for EndpointWWMicrosoft Monitoring Agent (MMA)443*.ods.opinsights.azure.com
Microsoft Defender for EndpointWWMicrosoft Monitoring Agent (MMA)443*.oms.opinsights.azure.com
Microsoft Defender for EndpointWWMicrosoft Monitoring Agent (MMA)443*.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443unitedstates.x.cp.wd.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443us.vortex-win.data.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443us-v20.events.data.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443winatp-gw-cus.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443winatp-gw-eus.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443winatp-gw-cus3.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443winatp-gw-eus3.microsoft.com
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443automatedirstrprdcus.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443automatedirstrprdeus.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443automatedirstrprdcus3.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443automatedirstrprdeus3.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus1eastprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus2eastprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus3eastprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus4eastprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443wsus1eastprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443wsus2eastprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus1westprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus2westprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus3westprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443ussus4westprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443wsus1westprod.blob.core.windows.net
Microsoft Defender for EndpointUSMicrosoft Defender for Endpoint US443wsus2westprod.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443europe.x.cp.wd.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443eu.vortex-win.data.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443eu-v20.events.data.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443winatp-gw-neu.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443winatp-gw-weu.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443winatp-gw-neu3.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443winatp-gw-weu3.microsoft.com
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443automatedirstrprdneu.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443automatedirstrprdweu.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443automatedirstrprdneu3.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443automatedirstrprdweu3.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443usseu1northprod.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443wseu1northprod.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443usseu1westprod.blob.core.windows.net
Microsoft Defender for EndpointEUMicrosoft Defender for Endpoint EU443wseu1westprod.blob.core.windows.net
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443unitedkingdom.x.cp.wd.microsoft.com
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443uk.vortex-win.data.microsoft.com
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443uk-v20.events.data.microsoft.com
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443winatp-gw-uks.microsoft.com
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443winatp-gw-ukw.microsoft.com
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443automatedirstrprduks.blob.core.windows.net
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443automatedirstrprdukw.blob.core.windows.net
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443ussuk1southprod.blob.core.windows.net
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443wsuk1southprod.blob.core.windows.net
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443ussuk1westprod.blob.core.windows.net
Microsoft Defender for EndpointUKMicrosoft Defender for Endpoint UK443wsuk1westprod.blob.core.windows.net
Microsoft Defender AntivirusWWUTC443vortex-win.data.microsoft.com
Microsoft Defender AntivirusWWMU / WU443*.update.microsoft.com
Microsoft Defender AntivirusWWMU / WU443*.delivery.mp.microsoft.com
Microsoft Defender AntivirusWWMU / WU443*.windowsupdate.com
Microsoft Defender AntivirusWWMU / WU443go.microsoft.com
Microsoft Defender AntivirusWWMU / WU443definitionupdates.microsoft.com
Microsoft Defender AntivirusWWMU / WU443https://www.microsoft.com/security/encyclopedia/adlpackages.aspx
Microsoft Defender AntivirusWWMU (ADL)443*.download.windowsupdate.com
Microsoft Defender AntivirusWWMU (ADL)443*.download.microsoft.com
Microsoft Defender AntivirusWWMU (ADL)443fe3cr.delivery.mp.microsoft.com/ClientWebService/client.asmx
Microsoft Defender AntivirusWWSymbols443https://msdl.microsoft.com/download/symbols
Microsoft Defender AntivirusWWMAPS443*.wdcp.microsoft.com
Microsoft Defender AntivirusWWMAPS443*.wd.microsoft.com
Microsoft Defender SmartScreenWWReporting and Notifications443*.smartscreen-prod.microsoft.com
Microsoft Defender SmartScreenWWReporting and Notifications443*.smartscreen.microsoft.com
Microsoft Defender SmartScreenWWReporting and Notifications443*.checkappexec.microsoft.com
Microsoft Defender SmartScreenWWReporting and Notifications443*.urs.microsoft.com
Azure Arc AgentWWUsed to resolve the download script during installationaka.ms
Azure Arc AgentWWUsed to download the Windows installation packagedownload.microsoft.com
Azure Arc AgentWWUsed to download the Linux installation packagepackages.microsoft.com
Azure Arc AgentWWAzure Active Directorylogin.windows.net
Azure Arc AgentWWAzure Active Directorylogin.microsoftonline.com
Azure Arc AgentWWAzure Active Directorypas.windows.net
Azure Arc AgentWWAzure Resource Manager - to create or delete the Arc server resourcemanagement.azure.com
Azure Arc AgentWWMetadata and hybrid identity services*.his.arc.azure.com
Azure Arc AgentWWExtension management and guest configuration services*.guestconfiguration.azure.com
Azure Arc AgentWWNotification service for extension and connectivity scenariosguestnotificationservice.azure.com,*.guestnotificationservice.azure.com
Azure Arc AgentWWNotification service for extension and connectivity scenariosazgn*.servicebus.windows.net
Azure Arc AgentWWFor Windows Admin Center and SSH scenarios*.servicebus.windows.net
Azure Arc AgentWWDownload source for Azure Arc-enabled servers extensions*.blob.core.windows.net
Azure Arc AgentWWAgent telemetrydc.services.visualstudio.com
Log Analytics Agent/Microsoft Monitoring AgentWW443*.ods.opinsights.azure.com
Log Analytics Agent/Microsoft Monitoring AgentWW443*.oms.opinsights.azure.com
Log Analytics Agent/Microsoft Monitoring AgentWW443*.blob.core.windows.net
Log Analytics Agent/Microsoft Monitoring AgentWW443*.azure-automation.net
Azure Monitor AgentWWAccess control service443global.handler.control.monitor.azure.com
Azure Monitor AgentWWFetch data collection rules for specific machine443*.handler.control.monitor.azure.com