The Defender for Endpoint allow-list used to be a long spreadsheet of regional URLs that changed just often enough to break someone's onboarding. Streamlined connectivity collapses the core service traffic into one wildcard domain and has been the default for new onboarding since May 2024, but existing devices do not move on their own, and old proxy rules are where migrations stall. In this post I'll cover what the consolidated domain does and does not replace, the prerequisites, onboarding and migration, the two proxy configurations, and how to prove a device really switched.
How it works#
Devices onboarded with the streamlined package send five categories of traffic to a single domain: cloud-delivered protection (MAPS), malware sample submission storage, automated investigation and remediation sample storage, the EDR command-and-control channel, and cyber and diagnostic data. For commercial tenants that domain is *.endpoint.security.microsoft.com; US Government clouds use *.endpoint.security.microsoft.us, still in preview. Features and user experience do not change; only the destinations do.
Three rules follow. The connections use certificate pinning, so TLS inspection on this domain breaks the sensor. They are device-initiated from the system account, so a proxy that enforces user authentication breaks them too. And the consolidated domain does not replace supporting endpoints: SmartScreen, update and certificate revocation traffic still need to be allowed. Microsoft has no plan to retire the standard URLs, but every device, standard or streamlined, should already reach the consolidated domain because future services are published there, and new Defender regions start on streamlined and cannot switch to standard.
If your firewall cannot do wildcard rules, use the Azure service tags MicrosoftDefenderForEndpoint (MAPS, sample storage, command and control) plus OneDsCollector for cyber and diagnostic data; the second tag is easy to forget and also carries telemetry for other Microsoft services.
Prerequisites#
| Component | Minimum version |
|---|---|
| Defender for Endpoint sensor (SENSE) | 10.8040.* (March 2022) or later, delivered through the March 2022 cumulative updates such as KB5011493 for Windows 11 and KB5011503 for Windows 10 1809 and Server 2019 |
| Microsoft Defender Antivirus platform | 4.18.2211.5 (November 2022) or later |
| Microsoft Defender Antivirus engine | 1.1.19900.2 (November 2022) or later |
| Security intelligence | 1.391.345.0 (June 2023) or later |
| Defender for Endpoint on macOS and Linux | 101.24022.* (March 2024) or later |
Supported operating systems are Windows 11, Windows 10 1809 and later, Windows Server 2019 and later, Windows Server 2012 R2 and 2016 on the modern unified solution (the MSI-based agent), supported macOS and Linux builds, and Azure Stack HCI 23H2 or later. Windows 10 1607 to 1803 can use the streamlined package but still need the longer URL list and cannot be re-onboarded in place. Anything still on the Microsoft Monitoring Agent stays on standard connectivity.
Step-by-step#
1. Allow the right destinations#
| Destination | Purpose | Required? |
|---|---|---|
*.endpoint.security.microsoft.com | All core Defender for Endpoint services | Required, all platforms |
*.smartscreen-prod.microsoft.com, *.smartscreen.microsoft.com | SmartScreen, network protection, web content filtering, custom URL and IP indicators | Required (optional only in disconnected environments; always required for custom indicators) |
*.checkappexec.microsoft.com, *.urs.microsoft.com | SmartScreen application reputation | Optional, Windows |
reflector.defender.microsoft.com | IPv6 connectivity probe | Optional |
https://config.edge.skype.com/config/v1 | Internal configuration for Defender on Linux (legacy name, unrelated to Skype) | Required, Linux |
| Windows Update and Microsoft Update endpoints | Platform, engine and security intelligence updates | Optional only when updates come from WSUS, Configuration Manager or a file share |
| Certificate revocation (CRL) endpoints | Certificate validation for the TLS connections above | Required |
Exclude the consolidated domain from HTTPS inspection, and keep the old standard URLs allowed until every device has been verified on the new path.
2. Configure the proxies (there are two)#
The EDR sensor runs as LocalSystem and uses WinHTTP, so Internet Explorer or Edge user proxy settings do not apply. Pick one of: a transparent proxy or WPAD (nothing to configure), a system-wide WinHTTP proxy, or a sensor-specific static proxy.
netsh winhttp set proxy 10.0.0.6:8080
netsh winhttp show proxy
netsh winhttp reset proxyFor the sensor-only option, use Group Policy under Computer Configuration › Policies › Administrative Templates › Windows Components › Data Collection and Preview Builds: enable Configure connected user experiences and telemetry with server:port (no scheme, no spaces), and enable Configure Authenticated Proxy usage for the Connected User Experience and Telemetry Service set to Disable Authenticated Proxy usage. They write TelemetryProxyServer (REG_SZ) and DisableEnterpriseAuthProxy = 1 under HKLM\Software\Policies\Microsoft\Windows\DataCollection. Microsoft explicitly says not to deliver TelemetryProxyServer through MDM; the sensor reads the Group Policy location. If the device cannot use the WinHTTP proxy for CRL or Windows Update traffic, add PreferStaticProxyForHttpRequest = 1 under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection (sensor 10.8210.* or 10.8049.* and later).
Microsoft Defender Antivirus has its own proxy for cloud protection. Configure it with the Group Policy Define proxy server for connecting to the network under Windows Components › Microsoft Defender Antivirus, which writes ProxyServer under HKLM\Software\Policies\Microsoft\Windows Defender, or with PowerShell:
Set-MpPreference -ProxyServer "http://10.0.0.6:8080"
Set-MpPreference -ProxyBypass "intranet.contoso.com"
Get-MpPreference | Select-Object ProxyServer, ProxyPacUrl, ProxyBypassNote: Defender for Endpoint needs IPv4. On IPv6-only networks you need DNS64/NAT64 end to end.
3. Test before you onboard#
Download the streamlined onboarding package, extract the .cmd, download and extract the MDE Client Analyzer, then run it from its folder in an elevated prompt. On a device that is not yet onboarded the analyzer tests the standard URL set by default, so point it at the package or a region:
mdeclientanalyzer.cmd -o "C:\Temp\<onboarding script>.cmd"
mdeclientanalyzer.cmd -g EUOpen MDEClientAnalyzerResult.txt: each URL is tested through the default proxy, WPAD, no proxy and any named proxy, and one Succeeded (200) per URL is enough. The analyzer's cloud checks conflict with the ASR rule Block process creations originating from PSExec and WMI commands; set an exclusion or disable the rule temporarily on the test device.
4. Onboard new devices#
In the Defender portal open Settings › Endpoints › Onboarding, choose the operating system group, set Connectivity type to Streamlined, pick the deployment method and download the package. Two tenant-level switches on the Settings › Endpoints › Optional features page (the page many admins still know as Advanced features) decide the default: Default to streamlined connectivity when onboarding devices in Defender portal, and Apply streamlined connectivity settings to devices managed by Intune and Defender for Cloud. The second one affects newly onboarded devices only.
5. Migrate devices that are already onboarded#
Offboarding is not required. Deploy the streamlined package with Intune, Group Policy, Configuration Manager, Jamf Pro or a local script, then reboot Windows devices; on macOS restart the daemon with launchctl unload and load of /Library/LaunchDaemons/com.microsoft.fresno.plist, and on Linux run sudo systemctl restart mdatp. Exclude migrated devices from any policy that still carries the standard package, otherwise it is reapplied at the next check-in. Start with a small ring, keep the standard URLs open as your rollback (reapplying the standard package reverts the device), and only remove the old core URLs after validation. Windows 10 1607 to 1803 must be fully offboarded and onboarded again.
Verify#
DeviceInfo
| where OnboardingStatus == "Onboarded"
| summarize arg_max(Timestamp, ConnectivityType, OSPlatform) by DeviceName
| summarize count() by OSPlatform, ConnectivityTypeConnectivityType in the DeviceInfo table is Streamlined once the device has spoken to the EDR command-and-control channel on the new domain, Standard if a standard package was (re)applied, and blank for devices that never re-onboarded. On a Windows device, open Applications and Services Logs › Microsoft › Windows › SENSE › Operational and look for event ID 4, which logs successful contact with a processing server; the URI should end in endpoint.security.microsoft.com. Event ID 5 records connection errors. On macOS and Linux, mdatp health --details edr should show edr_partner_geo_location as GW_<geo>, and mdatp connectivity test should return the new domain for the storage, mdav, xplat and packages checks. Finish with MpCmdRun.exe -ValidateMapsConnection for cloud protection and confirm the device kept the same device ID in the inventory.
Tips and gotchas#
| What you see | What it usually means |
|---|---|
ConnectivityType stays blank after deployment | The package ran but the device was not rebooted (Windows) or the service was not restarted (macOS and Linux) |
| Device flips back to Standard | An old onboarding policy or script still targets it and reapplied the standard package |
| Analyzer fails on every URL behind the proxy | Authenticated proxy or HTTPS inspection on the consolidated domain; the sensor cannot do either |
| Streamlined works, but updates or SmartScreen stop | Only the core domain was allowed; the supporting endpoints were dropped |
| Static IP rules work for EDR but telemetry fails | OneDsCollector ranges were not added alongside MicrosoftDefenderForEndpoint |
| Server 2012 R2 or 2016 never switches | Still on the Microsoft Monitoring Agent; upgrade to the modern unified solution first |
Tip: when TelemetryProxyServer is configured, the sensor falls back to a direct connection if the proxy is unreachable. Make sure your firewall allows that path too, or the fallback becomes a silent failure.