Unable to configure Microsoft XDR connector in Sentinel
Hi
Currently, it is not possible to configure the Microsoft Defender XDR connector via browser from Switzerland. Access to the URL https://partnersgw.securitycenter.windows.com/api/mdgw/sentinel/workspaces/isOnboarded is blocked unless a Microsoft public IP (Azure or Global Secure Access) is used. As a result, it is not possible to check the checkboxes:
The DNS alias resolution for partnersgw.securitycenter.windows.com from Switzerland is as follows:
Non-authoritative answer:
Name: mps-mde-prd-swn0a-41-service-tag.switzerlandnorth.cloudapp.azure.com
Address: 74.242.225.148 **<- CH IP
**Aliases: partnersgw.securitycenter.windows.com k8stm-partners-prd.trafficmanager.net
To reproduce the problem, simply use a client with a non-Microsoft egress Public IP and access the URL https://mps-mde-prd-swn0a-41-service-tag.switzerlandnorth.cloudapp.azure.com:
As a workaround, I have configure the client’s hosts file as follows; this way it works, because currently the partnersgw with a U.S. IP address does not block connections from non-Microsoft public IPs:
But is this behavior intentional? If so, is it due to the migration of Sentinel from the Azure portal to Microsoft XDR? (seehttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender?tabs=MDE)? The problem is that from the Microsoft XDR Portal under sentinel I don't see the XDR connector, how can I configure is?
many thanks