Skip to content

Commit df0f4ca

Browse files
Merge pull request #241137 from dcurwin/arc-network-ports-june11-2023
Network ports for Azure Arc for Defender for Servers
2 parents 1ab10f2 + e4545e3 commit df0f4ca

File tree

2 files changed

+25
-9
lines changed

2 files changed

+25
-9
lines changed

articles/defender-for-cloud/plan-defender-for-servers-agents.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,7 @@ You can onboard the Azure Arc agent to your AWS or GCP servers automatically wit
4242
To plan for Azure Arc deployment:
4343

4444
1. Review the Azure Arc [planning recommendations](../azure-arc/servers/plan-at-scale-deployment.md) and [deployment prerequisites](../azure-arc/servers/prerequisites.md).
45+
1. Open the [network ports for Azure Arc](support-matrix-defender-for-servers.md#network-requirements) in your firewall.
4546
1. Azure Arc installs the Connected Machine agent to connect to and manage machines that are hosted outside of Azure. Review the following information:
4647

4748
- The [agent components and data collected from machines](../azure-arc/servers/agent-overview.md#agent-resources).

articles/defender-for-cloud/support-matrix-defender-for-servers.md

Lines changed: 24 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,20 +4,40 @@ description: Review support requirements for the Defender for Servers plan in Mi
44
ms.topic: limits-and-quotas
55
author: dcurwin
66
ms.author: dacurwin
7-
ms.date: 01/01/2023
7+
ms.date: 06/11/2023
88
---
99

1010
# Defender for Servers support
1111

1212
This article summarizes support information for the Defender for Servers plan in Microsoft Defender for Cloud.
1313

14-
## Azure cloud support
14+
## Network requirements
15+
16+
Validate the following endpoints are configured for outbound access so that Azure Arc extension can connect to Microsoft Defender for Cloud to send security data and events:
17+
18+
- For Defender for Server multicloud deployments, make sure that the [addresses and ports required by Azure Arc](../azure-arc/data/connectivity.md#details-on-internet-addresses-ports-encryption-and-proxy-server-support) are open.
19+
20+
- For deployments with GCP connectors, open port 443 to these URLs:
1521

22+
- `osconfig.googleapis.com`
23+
- `compute.googleapis.com`
24+
- `containeranalysis.googleapis.com`
25+
- `agentonboarding.defenderforservers.security.azure.com`
26+
- `gbl.his.arc.azure.com`
1627

17-
This table summarizes Azure cloud support for Defender for Servers features.
28+
- For deployments with AWS connectors, open port 443 to these URLs:
29+
30+
- `ssm.<region>.amazonaws.com`
31+
- `ssmmessages.<region>.amazonaws.com`
32+
- `ec2messages.<region>.amazonaws.com`
33+
- `gbl.his.arc.azure.com`
34+
35+
## Azure cloud support
36+
37+
This table summarizes Azure cloud support for Defender for Servers features.
1838

1939
**Feature/Plan** | **Azure** | **Azure Government** | **Azure China**<br/>**21Vianet**
20-
--- | --- | --- | ---
40+
--- | --- | --- | ---
2141
[Microsoft Defender for Endpoint integration](./integration-defender-for-endpoint.md) | GA | GA | NA
2242
[Compliance standards](./regulatory-compliance-dashboard.md)<br/>Compliance standards might differ depending on the cloud type.| GA | GA | GA
2343
[Microsoft Cloud Security Benchmark recommendations for OS hardening](apply-security-baseline.md) | GA | GA | GA
@@ -30,7 +50,6 @@ This table summarizes Azure cloud support for Defender for Servers features.
3050
[Adaptive network hardening](./adaptive-network-hardening.md) | GA | NA | NA
3151
[Docker host hardening](./harden-docker-hosts.md) | GA | GA | GA
3252

33-
3453
## Windows machine support
3554

3655
The following table shows feature support for Windows machines in Azure, Azure Arc, and other clouds.
@@ -107,8 +126,6 @@ The following table shows feature support for AWS and GCP machines.
107126
| [Network security assessment](protect-network-resources.md) | - | - |
108127
| [Cloud security explorer](how-to-manage-cloud-security-explorer.md) || - |
109128

110-
111-
112129
## Endpoint protection support
113130

114131
The following table provides a matrix of supported endpoint protection solutions. The table indicates whether you can use Defender for Cloud to install each solution for you.
@@ -125,12 +142,10 @@ The following table provides a matrix of supported endpoint protection solutions
125142
| Microsoft Defender for Endpoint Unified Solution<sup>[2](#footnote2)</sup> | Windows Server 2012 R2 and Windows 2016 | Via extension |
126143
| Sophos V9+ | Linux (GA) | No |
127144

128-
129145
<sup><a name="footnote1"></a>1</sup> It's not enough to have Microsoft Defender for Endpoint on the Linux machine: the machine will only appear as healthy if the always-on scanning feature (also known as real-time protection (RTP)) is active. By default, the RTP feature is **disabled** to avoid clashes with other AV software.
130146

131147
<sup><a name="footnote2"></a>2</sup> With the MDE unified solution on Server 2012 R2, it automatically installs Microsoft Defender Antivirus in Active mode. For Windows Server 2016, Microsoft Defender Antivirus is built into the OS.
132148

133149
## Next steps
134150

135151
Start planning your [Defender for Servers deployment](plan-defender-for-servers.md).
136-

0 commit comments

Comments
 (0)