You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/configure-device-connectivity.md
+15-13Lines changed: 15 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,7 +44,7 @@ The Defender for Endpoint-recognized simplified domain: `*.endpoint.security.mic
44
44
To support network devices without hostname resolution or wildcard support, you can alternatively configure connectivity using dedicated Defender for Endpoint static IP ranges. For more information, see [Configure connectivity using static IP ranges](#option-2-configure-connectivity-using-static-ip-ranges).
45
45
46
46
> [!NOTE]
47
-
> - The simplified connectivity method will **not change how Microsoft Defender for Endpoint functions on a device nor will it change the end-user experience**. Only the URLs or IPs that a device uses to connect to the service will change.
47
+
> - The streamlined connectivity method will **not change how Microsoft Defender for Endpoint functions on a device nor will it change the end-user experience**. Only the URLs or IPs that a device uses to connect to the service will change.
48
48
> - There currently is no plan to deprecate the old, consolidated service URLs. Devices onboarded with "standard" connectivity will continue to function. It is important to ensure connectivity to *.endpoint.security.microsoft.com is and remains possible, as future services will require it. This new URL is included in all required URL lists.
49
49
50
50
## Consolidated services
@@ -134,7 +134,7 @@ The following illustration shows the streamlined connectivity process and the co
134
134
135
135
Once you confirm prerequisites are met, ensure your network environment is properly configured to support the streamlined connectivity method. Follow the steps outlined in [Configure your network environment to ensure connectivity with Defender for Endpoint service](configure-environment.md).
136
136
137
-
Defender for Endpoint services consolidated under the simplified method should no longer be required for connectivity. However, some URLs aren't included in the consolidation.
137
+
Defender for Endpoint service URLs consolidated under simplified domain the should no longer be required for connectivity. However, some URLs aren't included in the consolidation.
138
138
139
139
Streamlined connectivity allows you to use the following option to configure cloud connectivity:
140
140
@@ -208,32 +208,34 @@ Once you configure your network to communicate with the full list of services, y
208
208
Before proceeding, confirm devices meet the [prerequisites](#prerequisites) and have updated the sensor and Microsoft Defender Antivirus versions.
209
209
210
210
211
-
To get the new package, in Microsoft Defender XDR, select **Settings > Endpoints > Device management> Onboarding**.
211
+
1.To get the new package, in Microsoft Defender XDR, select **Settings > Endpoints > Device management> Onboarding**.
212
212
213
+
2. Select the applicable operating system and choose "Streamlined" from the Connectivity type dropdown menu.
213
214
214
-
Select the applicable operating system and choose "Streamlined (preview)" from the Connectivity type dropdown menu.
215
-
216
-
For new devices (not onboarded to Defender for Endpoint) supported under this method, follow onboarding steps from previous sections using the updated onboarded package with your preferred deployment method:
215
+
3. For new devices (not onboarded to Defender for Endpoint) supported under this method, follow onboarding steps from previous sections using the updated onboarded package with your preferred deployment method:
217
216
218
217
-[Onboard Windows Client](onboard-windows-client.md)
219
218
-[Onboard Windows Server](configure-server-endpoints.md)
-[Run a detection test on a device to verify it has been properly onboarded to Microsoft Defender for Endpoint](run-detection-test.md)
222
221
223
222
224
-
Exclude devices from any existing onboarding policies that use the standard onboarding package.
223
+
4.Exclude devices from any existing onboarding policies that use the standard onboarding package.
225
224
226
225
For migrating devices already onboarded to Defender for Endpoint, see [Migrating devices to the streamlined connectivity](migrate-devices-streamlined.md). You must reboot your device and follow specific guidance here.
227
226
228
-
:::image type="content" source="media/migrate-devices-streamlined.png" alt-text="Screenshot of onboarding page with streamlined connectivity":::
227
+
### Stage 5. Set the default onboarding package to streamlined connectivity
229
228
229
+
When you're ready to set the default onboarding package to streamlined, you can turn on the following Advanced Feature setting in the Microsoft Defender portal (**Settings > Endpoints > Advanced Features**).
230
230
231
-
When you're ready to set the default onboarding package to streamlined, you can turn on the following Advanced Feature setting in the Microsoft Defender portal (**Settings > Endpoints > Advanced Features**). For onboarding through Intune & Microsoft Defender for Cloud, you will need to activate the relevant option. Devices already onboarded will not automatically re-onboard; you will need to create a new policy in Intune, where it is recommended to first assign the policy to a set of test devices to verify connectivity is successful, before expanding the audience. Devices in Defender for Cloud can be re-onboarded using the relevant onboarding script.
> Before moving forward with this option, validate that your environment is ready and all devices meet prerequisites.
233
+
This setting sets the default onboarding package to 'streamlined' for applicable operating systems. You can still use the standard onboarding package within the onboarding page but you must specifically select it in the drop-down.
235
234
235
+
For onboarding through Intune & Microsoft Defender for Cloud, you will need to activate the relevant option. Devices already onboarded will not automatically re-onboard; you will need to create a new policy in Intune, where it is recommended to first assign the policy to a set of test devices to verify connectivity is successful, before expanding the audience. Devices in Defender for Cloud can be re-onboarded using the relevant onboarding script.
236
+
237
+
> [!NOTE]
238
+
> - Only tenants created on or before May 8th, 2024 have the option to switch between standard and streamlined connectivity. Newer tenants will only support streamlined connectivity.
239
+
> - Before moving forward with this option, validate that your environment is ready and all devices meet prerequisites.
236
240
237
-
:::image type="content" source="media/advanced-setting-streamlined-connectivity.png" alt-text="Screenshot of advanced settings page with streamlined connectivity option":::
238
241
239
-
This setting sets the default onboarding package to 'streamlined' for applicable operating systems. You can still use the standard onboarding package within the onboarding page but you must specifically select it in the drop-down.
0 commit comments