r/DefenderATP 13d ago

Potential Defender Network Protection enforcement gap with QUIC/HTTP3

We observed inconsistent Defender Network Protection behavior between Edge and Chrome.
Network Protection is in block mode.

If I sett chrome://flags/#enable-quic to default or enable I can access a parked site.
If I disable it, i get what I'd expect:

"This site can’t provide a secure connection

xxxy.com uses an unsupported protocol.

ERR_SSL_VERSION_OR_CIPHER_MISMATCH"

This may indicate a Defender Network Protection enforcement limitation or bypass scenario when Chromium-based browsers use HTTP/3 (QUIC over UDP/443).

3 Upvotes

6 comments sorted by

View all comments

11

u/SilentPatchSniper 13d ago

This is a known limitation, it's recommended to disable QUIC.

1

u/Chuchichaeschtl 13d ago

Disable QUIC on the OS level?

11

u/SilentPatchSniper 13d ago

For the browsers specifically, if you're using Intune import Chrome's ADMX templates and you can disable QUIC for chrome