Skip to main content
๐Ÿฆ‰
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
๐Ÿฆ‰
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

ยฉ 2026 M365 Message Center. Created with โค๏ธ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center โ€ข Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1194061

IP address changes in Defender for Identity v2.x sensor communication

Informational

Message ID

MC1194061
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Identity v2.x sensors will start using new IP addresses from the AzureAdvancedThreatProtection service tag range beginning mid-December 2025. Organizations restricting outbound IPs must update firewall rules to allow this range to avoid connectivity loss; no action is needed if the full range is already allowed.

Details

Introduction

As part of ongoing infrastructure and security improvements, Microsoft Defender for Identity (MDI) v2.x sensors will begin using new IP addresses to communicate with the MDI cloud. These IPs will come exclusively from the published range associated with the service tag AzureAdvancedThreatProtection. This change improves reliability and aligns with Azure networking standards.

When this will happen:

General Availability (Worldwide, GCC, GCCH, DoD): Gradual rollout begins mid-December 2025.

How this affects your organization:

  • Who is affected: Organizations using Microsoft Defender for Identity v2.x sensors and restricting outbound traffic by IP address.
  • What will happen:
    • MDI sensors will start using new IP addresses from the published AzureAdvancedThreatProtection range.
    • No addresses outside the published range will be used.
    • Organizations that already allow the full published range will not experience any disruption.
    • If IP restrictions exist and are not updated, sensors may lose connectivity to the MDI cloud.

What you can do to prepare:

  • If your organization already allows the full published range, no action is needed.
  • Otherwise:
    • Review any firewall or network policies that restrict traffic to MDI by IP address.
    • Update policies to allow the full published IP range for the service tag AzureAdvancedThreatProtection. Learn more: Azure IP Ranges and Service Tags.

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Timeline

๐Ÿ“…
Published
Dec 10, 2025
Message published to Message Center
โœ๏ธ
Updated
Dec 10, 2025
Message content updated
๐Ÿ
End Date
Jan 31, 2026
Message timeline ends

Tags

#Feature update#User impact#Admin impact

Category

๐Ÿ“–Stay Informed

Related Messages

Similar updates

MC1192254

Microsoft Defender for Endpoint: New Microsoft Secure Score recommendations

Dec 5, 2025
MC1217650

Microsoft Defender for Cloud Apps รขโ‚ฌโ€œ Improvements to Microsoft 365 connector configuration page

Jan 14, 2026
MC1184997

Microsoft Defender for O365: New email actions available in Advanced Hunting

Nov 12, 2025
MC1192257โ—

Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel

Dec 5, 2025
MC1171845

Microsoft Defender for Office 365: Enhancing the quarantine experience for administrators

Oct 13, 2025