Request from the AKS to domain ami.cloud-dev.defender.microsoft.com

Kit Shing Kwong 5 Reputation points
2025-04-04T07:37:31.3166667+00:00

Hi,

We found there are requests to the domain ami.cloud-dev.defender.microsoft.com from the AKS begining few days ago. It is blocked by the outbound firewall. We want to whitelist the domain, but we cannot find it listed in https://learn.microsoft.com/en-us/azure/aks/outbound-rules-control-egress. May I know what this domain is for ?

Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
2,380 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Mounika Reddy Anumandla 4,300 Reputation points Microsoft External Staff
    2025-04-04T09:32:37.41+00:00

    Hi Kit Shing Kwong,

    Microsoft Defender for Containers is a cloud-native solution to enhance, monitor, and maintain the security of your containerized assets (Kubernetes clusters, nodes, workloads, registries, images, and more) and their applications across multicloud and on-premises environments.
    Diagram of high-level architecture of the interaction between Microsoft Defender for Containers, Azure Kubernetes Service, and Azure Policy.

    To protect your Kubernetes containers, Defender for Containers receives and analyzes:

    To learn more about implementation details such as supported operating systems, feature availability, outbound proxy, see Defender for Containers feature availability.

    Hope this helps!

    Let me know if you have any further queries!

    If the information is helpful, please click "upvote" to let us know.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.