Microsoft Defender for Endpoint is a multi-platform cloud-based endpoint protection product that comprises multiple capabilities and features. There are many moving parts that make up Defender for En...
Thanks for the clarification. I believe that this links back to suggested practices when consuming Microsoft cloud services. Given that Microsoft's own "intranet" is the internet we've built our products around this conception. Ideally, as you stated, is having the endpoint communicate directly to the cloud endpoints (published via CDN) is the "easiest" method. This however, doesn't support all scenarios, especially disconnected environments due to regulation or other such requirements.
Using that approach should resolve any issues but it does seem intimidating. I really like the article by Ed Fisher to help explain this. You can also reach out to your FastTrack team. (https://fasttrack.microsoft.com) If you have at least 150 licenses (Requirements here: Eligibility - FastTrack β Microsoft 365 | Microsoft Learn) then they can help walk through the networking scenario and show you the different tools and methodologies available for optimization. Hope this helps π