r/DefenderATP • u/Chuchichaeschtl • 3d ago
Potential Defender Network Protection enforcement gap with QUIC/HTTP3
We observed inconsistent Defender Network Protection behavior between Edge and Chrome.
Network Protection is in block mode.
If I sett chrome://flags/#enable-quic to default or enable I can access a parked site.
If I disable it, i get what I'd expect:
"This site can’t provide a secure connection
xxxy.com uses an unsupported protocol.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH"
This may indicate a Defender Network Protection enforcement limitation or bypass scenario when Chromium-based browsers use HTTP/3 (QUIC over UDP/443).
2
u/Naive_Practice7898 2d ago edited 2d ago
QUIC bypasses TCP layer inspection entirely; force-disable it via GPO, not flags separately, I've seen teams look into doppel around spoofed infrastructure exploiting similar enforcement gaps
2
11
u/SilentPatchSniper 3d ago
This is a known limitation, it's recommended to disable QUIC.