Unable to configure Microsoft XDR connector in Sentinel

Reeno 0 Reputation points
2025-10-31T11:02:33.64+00:00

Hi

Currently, it is not possible to configure the Microsoft Defender XDR connector via browser from Switzerland. Access to the URL https://partnersgw.securitycenter.windows.com/api/mdgw/sentinel/workspaces/isOnboarded is blocked unless a Microsoft public IP (Azure or Global Secure Access) is used. As a result, it is not possible to check the checkboxes:

Browser

The DNS alias resolution for partnersgw.securitycenter.windows.com from Switzerland is as follows:

Non-authoritative answer:
Name: mps-mde-prd-swn0a-41-service-tag.switzerlandnorth.cloudapp.azure.com
Address: 74.242.225.148 **<- CH IP
**Aliases: partnersgw.securitycenter.windows.com k8stm-partners-prd.trafficmanager.net

To reproduce the problem, simply use a client with a non-Microsoft egress Public IP and access the URL https://mps-mde-prd-swn0a-41-service-tag.switzerlandnorth.cloudapp.azure.com:

User's image

As a workaround, I have configure the client’s hosts file as follows; this way it works, because currently the partnersgw with a U.S. IP address does not block connections from non-Microsoft public IPs:

User's image

But is this behavior intentional? If so, is it due to the migration of Sentinel from the Azure portal to Microsoft XDR? (seehttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender?tabs=MDE)? The problem is that from the Microsoft XDR Portal under sentinel I don't see the XDR connector, how can I configure is?

many thanks

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.