Skip to content

Commit 62cc734

Browse files
authored
Update configure-device-connectivity.md
1 parent 0a1080c commit 62cc734

File tree

1 file changed

+15
-13
lines changed

1 file changed

+15
-13
lines changed

defender-endpoint/configure-device-connectivity.md

Lines changed: 15 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ The Defender for Endpoint-recognized simplified domain: `*.endpoint.security.mic
4444
To support network devices without hostname resolution or wildcard support, you can alternatively configure connectivity using dedicated Defender for Endpoint static IP ranges. For more information, see [Configure connectivity using static IP ranges](#option-2-configure-connectivity-using-static-ip-ranges).
4545

4646
> [!NOTE]
47-
> - The simplified connectivity method will **not change how Microsoft Defender for Endpoint functions on a device nor will it change the end-user experience**. Only the URLs or IPs that a device uses to connect to the service will change.
47+
> - The streamlined connectivity method will **not change how Microsoft Defender for Endpoint functions on a device nor will it change the end-user experience**. Only the URLs or IPs that a device uses to connect to the service will change.
4848
> - There currently is no plan to deprecate the old, consolidated service URLs. Devices onboarded with "standard" connectivity will continue to function. It is important to ensure connectivity to *.endpoint.security.microsoft.com is and remains possible, as future services will require it. This new URL is included in all required URL lists.
4949
5050
## Consolidated services
@@ -134,7 +134,7 @@ The following illustration shows the streamlined connectivity process and the co
134134

135135
Once you confirm prerequisites are met, ensure your network environment is properly configured to support the streamlined connectivity method. Follow the steps outlined in [Configure your network environment to ensure connectivity with Defender for Endpoint service](configure-environment.md).
136136

137-
Defender for Endpoint services consolidated under the simplified method should no longer be required for connectivity. However, some URLs aren't included in the consolidation.
137+
Defender for Endpoint service URLs consolidated under simplified domain the should no longer be required for connectivity. However, some URLs aren't included in the consolidation.
138138

139139
Streamlined connectivity allows you to use the following option to configure cloud connectivity:
140140

@@ -208,32 +208,34 @@ Once you configure your network to communicate with the full list of services, y
208208
Before proceeding, confirm devices meet the [prerequisites](#prerequisites) and have updated the sensor and Microsoft Defender Antivirus versions.
209209

210210

211-
To get the new package, in Microsoft Defender XDR, select **Settings > Endpoints > Device management> Onboarding**.
211+
1. To get the new package, in Microsoft Defender XDR, select **Settings > Endpoints > Device management> Onboarding**.
212212

213+
2. Select the applicable operating system and choose "Streamlined" from the Connectivity type dropdown menu.
213214

214-
Select the applicable operating system and choose "Streamlined (preview)" from the Connectivity type dropdown menu.
215-
216-
For new devices (not onboarded to Defender for Endpoint) supported under this method, follow onboarding steps from previous sections using the updated onboarded package with your preferred deployment method:
215+
3. For new devices (not onboarded to Defender for Endpoint) supported under this method, follow onboarding steps from previous sections using the updated onboarded package with your preferred deployment method:
217216

218217
- [Onboard Windows Client](onboard-windows-client.md)
219218
- [Onboard Windows Server](configure-server-endpoints.md)
220219
- [Onboard non-Windows devices](configure-endpoints-non-windows.md)
221220
- [Run a detection test on a device to verify it has been properly onboarded to Microsoft Defender for Endpoint](run-detection-test.md)
222221

223222

224-
Exclude devices from any existing onboarding policies that use the standard onboarding package.
223+
4. Exclude devices from any existing onboarding policies that use the standard onboarding package.
225224

226225
For migrating devices already onboarded to Defender for Endpoint, see [Migrating devices to the streamlined connectivity](migrate-devices-streamlined.md). You must reboot your device and follow specific guidance here.
227226

228-
:::image type="content" source="media/migrate-devices-streamlined.png" alt-text="Screenshot of onboarding page with streamlined connectivity":::
227+
### Stage 5. Set the default onboarding package to streamlined connectivity
229228

229+
When you're ready to set the default onboarding package to streamlined, you can turn on the following Advanced Feature setting in the Microsoft Defender portal (**Settings > Endpoints > Advanced Features**).
230230

231-
When you're ready to set the default onboarding package to streamlined, you can turn on the following Advanced Feature setting in the Microsoft Defender portal (**Settings > Endpoints > Advanced Features**). For onboarding through Intune & Microsoft Defender for Cloud, you will need to activate the relevant option. Devices already onboarded will not automatically re-onboard; you will need to create a new policy in Intune, where it is recommended to first assign the policy to a set of test devices to verify connectivity is successful, before expanding the audience. Devices in Defender for Cloud can be re-onboarded using the relevant onboarding script.
231+
<img width="593" alt="image" src="https://github.com/MicrosoftDocs/defender-docs-pr/assets/30799281/3509aeec-bbab-4efd-a328-0608a11cc6d1">
232232

233-
> [!NOTE]
234-
> Before moving forward with this option, validate that your environment is ready and all devices meet prerequisites.
233+
This setting sets the default onboarding package to 'streamlined' for applicable operating systems. You can still use the standard onboarding package within the onboarding page but you must specifically select it in the drop-down.
235234

235+
For onboarding through Intune & Microsoft Defender for Cloud, you will need to activate the relevant option. Devices already onboarded will not automatically re-onboard; you will need to create a new policy in Intune, where it is recommended to first assign the policy to a set of test devices to verify connectivity is successful, before expanding the audience. Devices in Defender for Cloud can be re-onboarded using the relevant onboarding script.
236+
237+
> [!NOTE]
238+
> - Only tenants created on or before May 8th, 2024 have the option to switch between standard and streamlined connectivity. Newer tenants will only support streamlined connectivity.
239+
> - Before moving forward with this option, validate that your environment is ready and all devices meet prerequisites.
236240
237-
:::image type="content" source="media/advanced-setting-streamlined-connectivity.png" alt-text="Screenshot of advanced settings page with streamlined connectivity option":::
238241

239-
This setting sets the default onboarding package to 'streamlined' for applicable operating systems. You can still use the standard onboarding package within the onboarding page but you must specifically select it in the drop-down.

0 commit comments

Comments
 (0)