Forum Discussion

shockotechcom's avatar
shockotechcom
Iron Contributor
Oct 18, 2020

Azure ATP Sensor Proxy Authentication

All internet traffic in our org goes via a forward web proxy. It also has the capability to bypass SSL inspection should we need to. I have been looking at deploying the Azure ATP sensor to my domain controllers but security teams are uncomfortable with it's https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet. From the documentation it seems like you must use the WinHTTP proxy as the agent runs in the SYSTEM content but that essentially means anything running in that context has access to POST to the those URLs. Granted they are Microsoft URLs. I was wondering if the proxy can be setup just for the agent within it's config or if it supported certificate based proxy authentication or the like?

No RepliesBe the first to reply

Resources