Unable to configure Microsoft XDR connector in Sentinel

Reeno 0 Reputation points
2025-10-31T11:02:33.64+00:00

Hi

Currently, it is not possible to configure the Microsoft Defender XDR connector via browser from Switzerland. Access to the URL https://partnersgw.securitycenter.windows.com/api/mdgw/sentinel/workspaces/isOnboarded is blocked unless a Microsoft public IP (Azure or Global Secure Access) is used. As a result, it is not possible to check the checkboxes:

Browser

The DNS alias resolution for partnersgw.securitycenter.windows.com from Switzerland is as follows:

Non-authoritative answer:
Name: mps-mde-prd-swn0a-41-service-tag.switzerlandnorth.cloudapp.azure.com
Address: 74.242.225.148 **<- CH IP
**Aliases: partnersgw.securitycenter.windows.com k8stm-partners-prd.trafficmanager.net

To reproduce the problem, simply use a client with a non-Microsoft egress Public IP and access the URL https://mps-mde-prd-swn0a-41-service-tag.switzerlandnorth.cloudapp.azure.com:

User's image

As a workaround, I have configure the client’s hosts file as follows; this way it works, because currently the partnersgw with a U.S. IP address does not block connections from non-Microsoft public IPs:

User's image

But is this behavior intentional? If so, is it due to the migration of Sentinel from the Azure portal to Microsoft XDR? (seehttps://learn.microsoft.com/en-us/azure/sentinel/connect-microsoft-365-defender?tabs=MDE)? The problem is that from the Microsoft XDR Portal under sentinel I don't see the XDR connector, how can I configure is?

many thanks

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Prathista Ilango 670 Reputation points Microsoft Employee
    2025-11-21T14:12:12.2533333+00:00

    Hello Reeno,

    The following gives a detailed overview of transitioning Sentinel to Defender XDR.

    Connect Microsoft Sentinel to the Microsoft Defender portal - Unified security operations | Microsoft Learn

    Transition Your Microsoft Sentinel Environment to the Defender Portal | Microsoft Learn

    https://learn.microsoft.com/en-us/azure/sentinel/microsoft-365-defender-sentinel-integration?tabs=defender-portal#microsoft-sentinel-and-defender-xdr

    When you integrate Microsoft Sentinel and Defender XDR directly in the Microsoft Defender portal you can view Microsoft Sentinel data directly with the rest of your Defender incidents, alerts, vulnerabilities, and other security data.

    Hope that helps!

    If you found the information above helpful, please Click Yes. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.