Microsoft Defender for Identity v2.x sensors will start using new IP addresses from the AzureAdvancedThreatProtection service tag range beginning mid-December 2025. Organizations restricting outbound IPs must update firewall rules to allow this range to avoid connectivity loss; no action is needed if the full range is already allowed.
Introduction
As part of ongoing infrastructure and security improvements, Microsoft Defender for Identity (MDI) v2.x sensors will begin using new IP addresses to communicate with the MDI cloud. These IPs will come exclusively from the published range associated with the service tag AzureAdvancedThreatProtection. This change improves reliability and aligns with Azure networking standards.
When this will happen:
General Availability (Worldwide, GCC, GCCH, DoD): Gradual rollout begins mid-December 2025.
How this affects your organization:
What you can do to prepare:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.