Forum Discussion
CyrilChu
Jun 07, 2023Copper Contributor
Network requirement/Firewall Whitelisting for Microsoft Sentinel
Hi Experts,
If I set up a CEF log forwarder in the on-premise environment with limited access, it will send the log to Sentinel.
How many IP addresses or Domains that I need to allow in the firewall policy?
From my understanding, Microsoft Sentinel is on top of other Services such as Azure Monitor.
https://learn.microsoft.com/en-us/azure/azure-monitor/app/ip-addresses#outgoing-ports
Do I need to allow all the IP addresses used by Azure Monitor?
1 Reply
- BillClarksonAntillIron Contributor
CyrilChu Check out this link, this should help you
https://www.microsoft.com/en-US/download/details.aspx?id=56519
For the Microsoft Sentinel IP ranges they are enclosed within that list (theres a list for Azure Sentinel), check it out