Forum Discussion

burnettc's avatar
burnettc
Copper Contributor
Nov 23, 2020

Defender for Endpoint alert delays

Hello,

We are rolling out defender for endpoint to our big windows estate. The first batch of on boarding and subsequent testing is showing huge delays on any alerts showing in the portal (6+ hours) Has anyone had any similar experiences when configuring and rolling out Defender for Endpoint?
  • BillTheKid's avatar
    BillTheKid
    Brass Contributor

    burnettcmultiply hours is not fine. I see alerts mostly popping up after 2 minutes of delay. Maybe this was caused by delays from your proxy to the backends? Check this here, to see what connections endpoints make. There is also a sheet with all IPs and connections which Defender does. Make sure, there was no bottleneck during deployment phase to these IPs/DNS/URLs. If you open the sheet, go to the left side to see all URLs. Maybe these devices had problems communicating with backend.

  • Thijs Lecomte's avatar
    Thijs Lecomte
    Bronze Contributor
    Just wanted to chime in and let you know that a customer of mine reported the same thing. They said MDfE was slow last week and were seeing huge delays in alerts

Resources