FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Dongfang_Li_FTNT
Article Id 284854
Description There is no Internet Service Database(ISDB) for Windows defender, which is typically necessary to allow applications in a FortiGate firewall policy. This article describes how to allow Windows Defender in a firewall policy regardless.
Scope FortiGate, all firmware.
Solution

According to this Microsoft article, Microsoft only publishes FQDNs for Microsoft Defender. The IP addresses resolved from them may be changed dynamically. ISDB is a static IP-based service which cannot handle FQDN or dynamic IPs directly. It is recommended to use an FQDN Address for these FQDNs, which can retrieve the latest IP addresses resolved from them in the environment.

 

The FQDNs for Windows Defender objects are as follows.

 

Used by Windows Defender for multiple platforms (Microsoft-Web object):

  • *.wdcp.microsoft.com
  • *.wdcpalt.microsoft.com
  • *.wd.microsoft.com

Used by Windows Update service (Microsoft-Micorsoft.Update object):

Used by multiple services, hosted on Azure (Microsoft-Azure obejct):

  • ussus1eastprod.blob.core.windows.net
  • ussus2eastprod.blob.core.windows.net
  • ussus3eastprod.blob.core.windows.net
  • ussus4eastprod.blob.core.windows.net
  • wsus1eastprod.blob.core.windows.net
  • wsus2eastprod.blob.core.windows.net
  • ussus1westprod.blob.core.windows.net
  • ussus2westprod.blob.core.windows.net
  • ussus3westprod.blob.core.windows.net
  • ussus4westprod.blob.core.windows.net
  • wsus1westprod.blob.core.windows.net
  • wsus2westprod.blob.core.windows.net
  • usseu1northprod.blob.core.windows.net
  • wseu1northprod.blob.core.windows.net
  • usseu1westprod.blob.core.windows.net
  • wseu1westprod.blob.core.windows.net
  • ussuk1southprod.blob.core.windows.net
  • wsuk1southprod.blob.core.windows.net
  • ussuk1westprod.blob.core.windows.net
  • wsuk1westprod.blob.core.windows.net

Used by multiple Microsoft services (Microsoft-Web object):