Our windows defender is not connecting to the Microsoft portal, then when i run the script from Microsoft i can see the traffic to winatp-gw-cus.microsoft.com is blocked.
From the microsoft documentation there are several winatp subdomain such as :
winatp-gw-aue.microsoft.com
winatp-gw-aus.microsoft.com
winatp-gw-neu.microsoft.com
winatp-gw-weu.microsoft.com
winatp-gw-neu3.microsoft.com
winatp-gw-weu3.microsoft.com
winatp-gw-uks.microsoft.com
winatp-gw-ukw.microsoft.com
winatp-gw-cus.microsoft.com
winatp-gw-eus.microsoft.com
winatp-gw-cus3.microsoft.com
winatp-gw-eus3.microsoft.com
Then i try to make domain object .microsoft.com and the traffic still blocked.
So anyone here can help me to understanding about domain object in the checkpoint? What in my mind is when we create .microsoft.com this same with *.microsoft.com and all hosts and sub domains under microsoft.com will be permitted.