Description | There is no Internet Service Database(ISDB) for Windows defender, which is typically necessary to allow applications in a FortiGate firewall policy. This article describes how to allow Windows Defender in a firewall policy regardless. |
Scope | FortiGate, all firmware. |
Solution |
According to this Microsoft article, Microsoft only publishes FQDNs for Microsoft Defender. The IP addresses resolved from them may be changed dynamically. ISDB is a static IP-based service which cannot handle FQDN or dynamic IPs directly. It is recommended to use an FQDN Address for these FQDNs, which can retrieve the latest IP addresses resolved from them in the environment.
The FQDNs for Windows Defender objects are as follows.
Used by Windows Defender for multiple platforms (Microsoft-Web object):
Used by Windows Update service (Microsoft-Micorsoft.Update object):
Used by multiple services, hosted on Azure (Microsoft-Azure obejct):
Used by multiple Microsoft services (Microsoft-Web object):
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.