Azure NSG rule to allow VM to access MS 365 Defender

601 Views Asked by At

I have a VNET which restricts all access outbound using an NSG except for 1 specific port which is used for an app it hosts. However I need a way to allow Defender to communicate with the MS 365 Defender portal so it can report in. I tried using a couple of the service tags (MS Cloud App security and ATP) but don't seem to work. Is there an IP or set of IPs I need to allow out for it to communicate?

1

There are 1 best solutions below

1
On

If it is the end point of the application you are protecting then:

MicrosoftDefenderForEndpoint

A full list of service tags is available here:

https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview