Azure Sentinel IP for WEST EUROPE

MS Techie 2,751 Reputation points
2021-11-25T12:21:11.1+00:00

Azure VM is protected by Sentinel

i need to find Azure Sentinel IPs . The intent is to whitelist these IPs from the Azure VM outbound IP

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Stanislav Zhelyazkov 28,596 Reputation points MVP Volunteer Moderator
    2021-11-29T13:50:31.57+00:00

    Hi,
    If you talking about the Log Analytics agent that is used by Azure Sentinel the firewall requirements are here. It is DNS records, not IPs as IPs change over time. For Azure VM it is better to use service tags. There is service tag for Azure Monitor. Read the documentation for it. Log Analytics is part of Azure Monitor and Azure Sentinel uses Log Analytics as platform for logs.

    For qualys extension there is no Service Tag. The communication of the extension is available here. You will need to open to specific DNS records https://qagpublic.qg3.apps.qualys.com - Qualys' US data center, https://qagpublic.qg2.apps.qualys.eu - Qualys' European data center rather IPs. Both for port 443.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.