Windows-itpro-docs: More specific whitelisting

Created on 25 Feb 2020  Â·  5Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

Is it possible to be more specific in the whitelisting as I'd prefer not to have to allow access to the entirety of Azure blob storage. Can you specify the Defender ATP specific blobs, rather than just everyone's Azure storage?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

defender for endpoint

Most helpful comment

Hello @kengoodwin,
as @phillym noticed, more detailed URLs could be found here.
Also, you can use the list of IP addresses published here, for example, to whitelist blob storage for Australia SE, you can use IP addresses marked with name "Storage.AustraliaSoutheast".

Thank you

@kengoodwin ‘s point, like mine before it is that it is unwise to exclude all of Azure blob storage from TLS interception and proxy auth, if those are controls you have in place already. Microsoft have specific buckets for these services and we need these to be explicitly documented so we only need to exclude the bucket DNS name and not every possible Azure Blob bucket.

@MaratMussabekov

All 5 comments

They’re still recommending the same for Mac clients too. Got fixed for Windows a while back and so far no issues with our Mac clients: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/4942

Hello @kengoodwin,
as @phillym noticed, more detailed URLs could be found here.
Also, you can use the list of IP addresses published here, for example, to whitelist blob storage for Australia SE, you can use IP addresses marked with name "Storage.AustraliaSoutheast".

Thank you

Hello @kengoodwin,
as @phillym noticed, more detailed URLs could be found here.
Also, you can use the list of IP addresses published here, for example, to whitelist blob storage for Australia SE, you can use IP addresses marked with name "Storage.AustraliaSoutheast".

Thank you

@kengoodwin ‘s point, like mine before it is that it is unwise to exclude all of Azure blob storage from TLS interception and proxy auth, if those are controls you have in place already. Microsoft have specific buckets for these services and we need these to be explicitly documented so we only need to exclude the bucket DNS name and not every possible Azure Blob bucket.

@MaratMussabekov

Dear @Dansimp,
could you please assist?
Thank you

@kengoodwin @phillym - Thank you for submitting feedback.

From our understanding, the issue has been resolved based on this merged commit https://github.com/MicrosoftDocs/windows-itpro-docs/commit/26b93c9.

Thank you for your contribution to make the docs better! Much appreciated!

Was this page helpful?
0 / 5 - 0 ratings

Related issues

RAJU2529 picture RAJU2529  Â·  3Comments

LanceMcCarthy picture LanceMcCarthy  Â·  3Comments

SwiftOnSecurity picture SwiftOnSecurity  Â·  3Comments

marcnil815 picture marcnil815  Â·  3Comments

sundhaug92 picture sundhaug92  Â·  3Comments