Microsoft Security | Microsoft Defender | Other
Additional Microsoft Defender tools and services that provide security across various platforms and environments
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I am wondering what urls I should exclude from ssl decryption when it comes to Microsoft defender.
Additional Microsoft Defender tools and services that provide security across various platforms and environments
AI answer
Exclude the Microsoft Defender endpoints that are used for protection, telemetry, updates, portal access, and certificate validation from SSL decryption. The context supports these key URLs and patterns:
*.wdcp.microsoft.com*.wdcpalt.microsoft.com*.wd.microsoft.com*.events.data.microsoft.com*ecs.office.com/config/v1/MicrosoftWindowsDefenderClient*.smartscreen-prod.microsoft.com*.smartscreen.microsoft.com*.update.microsoft.com*.delivery.mp.microsoft.com*.windowsupdate.comctldl.windowsupdate.com*.blob.core.windows.nethttps://*.microsoftonline-p.comhttps://secure.aadcdn.microsoftonline-p.comhttps://static2.sharepointonline.comhttps://login.microsoftonline.comhttps://*.securitycenter.windows.comhttps://*.api.security.microsoft.comhttps://security.microsoft.comenterpriseregistration.windows.net*.dm.microsoft.com*.ods.opinsights.azure.com*.oms.opinsights.azure.com*.blob.core.windows.net*.blob.core.windows.net/networkscannerstable/*crl.microsoft.com/pki/crl/*ctldl.windowsupdate.comwww.microsoft.com/pkiops/*http://www.microsoft.com/pki/certsNotes:
443 is used for the Defender connectivity URLs, and port 80 is also required for some certificate validation URLs.References: