SOLVED

Microsoft Defender for Endpoint - Network Issues

%3CLINGO-SUB%20id%3D%22lingo-sub-2149995%22%20slang%3D%22en-US%22%3EMicrosoft%20Defender%20for%20Endpoint%20-%20Network%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2149995%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20recently%20started%20onboarding%20our%20machines%20into%20the%20Microsoft%20Security%20Center%20and%20using%20Defender%20for%20Endpoint.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20doing%20so%2C%20we've%20noticed%20what%20seems%20to%20be%20related%20to%20how%20defender%20is%20handing%20network%20traffic.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIssue%201%20-%20We%20have%20an%20on-premise%20file%20share.%20When%20accessing%20network%20shares%20we're%20unable%20to%20open%20files%20randomly.%20We'll%20get%20generic%20errors%20like%20%22Sorry%20we%20couldn't%20find%20%5BFile%20Name%5D.%20Is%20it%20possible%20it%20was%20moved%2C%20renamed%20or%20deleted%3F%20and%20%22Microsoft%20Excel%20cannot%20access%20the%20file%20%5BFile%20Name%5D.%20There%20are%20several%20possible%20reasons%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20if%20we%20access%20the%20same%20files%20from%20a%20machine%20that%20has%20not%20been%20onboard%20yet%20there%20are%20no%20issues%20whatever%20so.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIssue%202%20-%20When%20accessing%20flow.microsoft.com%20from%20a%20machine%20with%20defender%20for%20endpoint%20enabled%2C%20I%20can%20not%20edit%20any%20flows%20or%20do%20any%20work.%20The%20flow%20constantly%20comes%20back%20as%20%22invalid%20connection%22.%20I've%20deleted%20and%20re-added%20the%20connection%20multiple%20times%2C%20re-authenticated%20etc%20and%20nothing%20seems%20to%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20same%20situation%20as%20above.%20When%20I%20access%20flow.microsoft.com%20from%20a%20machine%20that%20has%20not%20been%20onboarded%20yet%20there%20are%20no%20issues%20editing%20or%20working%20with%20the%20flows.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20disabled%20EDR%20in%20Block%20Mode%20and%20also%20the%20Customer%20network%20indicators%20just%20to%20see%20if%20it%20would%20help%20but%20no%20luck.%20So%20far%20the%20only%20thing%20that%20works%20is%20offboard%20the%20device.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2149995%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDefender%20for%20Endpoint%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Enetwork%20share%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eon-premise%20file%20share%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2150305%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Defender%20for%20Endpoint%20-%20Network%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2150305%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F615827%22%20target%3D%22_blank%22%3E%40SteveTheITDude%3C%2FA%3EDid%20you%20configure%20firewall%20rules%20either%20on%20MEM%20portal%20or%20via%20Group%20Policy%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2333475%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Defender%20for%20Endpoint%20-%20Network%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2333475%22%20slang%3D%22en-US%22%3EIm%20also%20experiencing%20the%20same%20issue.%20We%20have%20Server%202019%20and%20we%20configure%20windows%20firewall%20via%20GPO%20and%20have%20it%20disabled.%3CBR%20%2F%3EI%20have%20a%20case%20open%20right%20now%20but%20I%20also%20see%20some%20old%20article%20that%20dates%20back%20to%202018%20about%20this%20and%20supposedly%20was%20going%20to%20get%20fixed%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2336549%22%20slang%3D%22en-US%22%3ERe%3A%20Microsoft%20Defender%20for%20Endpoint%20-%20Network%20Issues%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2336549%22%20slang%3D%22en-US%22%3EHere's%20what%20ended%20up%20resolving%20my%20issues%20(although%20it%20sounds%20like%20it%20wont%20apply%20to%20your%20situation)%3CBR%20%2F%3E%3CBR%20%2F%3EIssue%201%20-%20File%20Shares%20-%20We%20discovered%20this%20was%20only%20happening%20on%20a%20file%20server%20that%20had%20Server%202012%20R2.%20We%20ended%20up%20upgrading%20the%20server%20to%202019%20and%20the%20issue%20disappeared.%3CBR%20%2F%3E%3CBR%20%2F%3EIssue%202%20-%20Access%20to%20Flow%20-%20Our%20DNS%20was%20also%20being%20filtered%20by%20a%20third%20party%20provider%20(DNSFilter).%20Once%20we%20disabled%20DNSFilter%20and%20just%20let%20Defender%20for%20Endpoint%20do%20the%20filtering%2C%20the%20access%20issues%20resolved.%3C%2FLINGO-BODY%3E
New Contributor

Hello,

 

We recently started onboarding our machines into the Microsoft Security Center and using Defender for Endpoint. 

 

After doing so, we've noticed what seems to be related to how defender is handing network traffic.

 

Issue 1 - We have an on-premise file share. When accessing network shares we're unable to open files randomly. We'll get generic errors like "Sorry we couldn't find [File Name]. Is it possible it was moved, renamed or deleted? and "Microsoft Excel cannot access the file [File Name]. There are several possible reasons".

 

However, if we access the same files from a machine that has not been onboard yet there are no issues whatever so. 

 

Issue 2 - When accessing flow.microsoft.com from a machine with defender for endpoint enabled, I can not edit any flows or do any work. The flow constantly comes back as "invalid connection". I've deleted and re-added the connection multiple times, re-authenticated etc and nothing seems to work.

 

However, same situation as above. When I access flow.microsoft.com from a machine that has not been onboarded yet there are no issues editing or working with the flows. 

 

I've disabled EDR in Block Mode and also the Customer network indicators just to see if it would help but no luck. So far the only thing that works is offboard the device. 

 

Thanks.

3 Replies

@SteveTheITDudeDid you configure firewall rules either on MEM portal or via Group Policy?

Im also experiencing the same issue. We have Server 2019 and we configure windows firewall via GPO and have it disabled.
I have a case open right now but I also see some old article that dates back to 2018 about this and supposedly was going to get fixed?
best response confirmed by SteveTheITDude (New Contributor)
Solution
Here's what ended up resolving my issues (although it sounds like it wont apply to your situation)

Issue 1 - File Shares - We discovered this was only happening on a file server that had Server 2012 R2. We ended up upgrading the server to 2019 and the issue disappeared.

Issue 2 - Access to Flow - Our DNS was also being filtered by a third party provider (DNSFilter). Once we disabled DNSFilter and just let Defender for Endpoint do the filtering, the access issues resolved.