<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updateable Objects: how to list members; which one(s) for Microsoft Defender for Endpoints? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134225#M24097</link>
    <description>&lt;P&gt;Np, dynamic objects one is a bit of a "hidden" one as it's not shown in command "help". Domains tools actually has it in the help.&lt;/P&gt;
&lt;P&gt;Remember that you can use -d flag to see actual IP addresses for specific domains and there you can see if it was resolved from wildcard entry (subdomain flag will be set to yes)&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 08:16:53 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2021-11-17T08:16:53Z</dc:date>
    <item>
      <title>Updateable Objects: how to list members; which one(s) for Microsoft Defender for Endpoints?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134176#M24088</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Struggling with opening least-privilege outbound permit rules for on-premise systems running (or to-be running) MS Defender for Endpoints (MDE).&amp;nbsp; Most ports are 80 or 443, so client systems generally don't have any issue; internal servers are a different matter.&lt;/P&gt;&lt;P&gt;MS provides the endpoints to which MDE-enabled systems need to connect here:&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-proxy-internet?view=o365-worldwide#enable-access-to-microsoft-defender-for-endpoint-service-urls-in-the-proxy-server" target="_blank"&gt;Configure device proxy and Internet connection settings | Microsoft Docs&lt;/A&gt;&amp;nbsp;(URL current as of writing, filename&amp;nbsp;mde-urls.xlsx).&amp;nbsp; However, there are many wildcarded entries, eg&lt;/P&gt;&lt;P&gt;*.wd.microsoft.com&lt;/P&gt;&lt;P&gt;*.oms.opinsights.azure.com&lt;/P&gt;&lt;P&gt;...in logs, I see test MDE boxes connecting to sub-sub-domains, eg&amp;nbsp;europe.cp.wd.microsoft.com, and I'm not sure Domain objects, (non-FQDN) would work efficiently (or at all?) with sub-sub-domains, nor that reverse look-ups will always work.&lt;/P&gt;&lt;P&gt;I'd (obviously) prefer to use built-in Updateable Objects, but the only apparently appropriate EU one is "Azure Advanced Threat Protection Public Services" - which the description states is derived from&amp;nbsp;&lt;A href="https://download.microsoft.com/download/7/1/D/71D86715-5596-4529-9B13-DA13A5DE5B63/ServiceTags_Public_20211115.json" target="_blank"&gt;https://download.microsoft.com/download/7/1/D/71D86715-5596-4529-9B13-DA13A5DE5B63/ServiceTags_Public_20211115.json&lt;/A&gt;&amp;nbsp;-&amp;nbsp; (&amp;gt;80k line JSON...)&lt;/P&gt;&lt;P&gt;After a while of successful testing, I note drops from test boxes, despite the Allow to "Azure Advanced Threat Protection Public Services" - I suspect that there are IPs in the MDE requirements that are not in the Azure list; it may be considered a completely different service (Defender docs are a mess, generally, and the interaction with Azure is obscure).&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;P&gt;- Is there a command I can use to dump the current contents (ie the specific IPs/ranges) in an Updateable Object?&lt;/P&gt;&lt;P&gt;- Is there (or will there be) an UO specific for Defender for Endpoints which will maintain/support the requirements in the first URL above?&lt;/P&gt;&lt;P&gt;Thanks if you got this far.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;auto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 17:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134176#M24088</guid>
      <dc:creator>autopoiesis</dc:creator>
      <dc:date>2021-11-16T17:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects: how to list members; which one(s) for Microsoft Defender for Endpoints?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134213#M24094</link>
      <description>&lt;P&gt;Answer to the first question, you will need to use two commands:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;dynamic_objects -uo_show&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;object name : CP_MS_Office365_Worldwide&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;range 0 : 13.107.6.152 13.107.6.153&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;range 1 : 13.107.6.171 13.107.6.171&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;range 2 : 13.107.18.10 13.107.18.11&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;...&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;STRONG&gt;domains_tool -uo "Office365 Worldwide Services"&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Domain tool looking for domains for 'Office365 Worldwide Services' and its children objects:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Domains name list for 'Skype for Business Online and Microsoft Teams Worldwide Services':&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[1] teams.microsoft.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[2] meetings.sfbassets.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[3] webdirca1.online.lync.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[4] cid-193d7751c51219f2.users.storage.live.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[5] *.skype.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;...&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 07:09:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134213#M24094</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-17T07:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects: how to list members; which one(s) for Microsoft Defender for Endpoints?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134216#M24095</link>
      <description>&lt;P&gt;Nothing to add to the discussion but thanks for sharing the commands - have often caught myself wishing I could see "inside" the UO's.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 07:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134216#M24095</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-11-17T07:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects: how to list members; which one(s) for Microsoft Defender for Endpoints?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134225#M24097</link>
      <description>&lt;P&gt;Np, dynamic objects one is a bit of a "hidden" one as it's not shown in command "help". Domains tools actually has it in the help.&lt;/P&gt;
&lt;P&gt;Remember that you can use -d flag to see actual IP addresses for specific domains and there you can see if it was resolved from wildcard entry (subdomain flag will be set to yes)&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 08:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134225#M24097</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-11-17T08:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects: how to list members; which one(s) for Microsoft Defender for Endpoints?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134354#M24109</link>
      <description>&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 09:15:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updateable-Objects-how-to-list-members-which-one-s-for-Microsoft/m-p/134354#M24109</guid>
      <dc:creator>autopoiesis</dc:creator>
      <dc:date>2021-11-18T09:15:00Z</dc:date>
    </item>
  </channel>
</rss>

