Azure ATP Sensor Proxy Authentication

shockoQA 126 Reputation points
2020-10-18T13:58:35.11+00:00

All internet traffic in our org goes via a forward web proxy. It also has the capability to bypass SSL inspection should we need to. I have been looking at deploying the Azure ATP sensor to my domain controllers but security teams are uncomfortable with it's egress requirements to the internet. From the documentation it seems like you must use the WinHTTP proxy as the agent runs in the SYSTEM content but that essentially means anything running in that context has access to POST to the those URLs. Granted they are Microsoft URLs. I was wondering if the proxy can be setup just for the agent within it's config or if it supported certificate based proxy authentication or the like?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,373 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.