Does Microsoft Defender Work in China? Endpoint Telemetry, Data Residency & the 21Vianet Sovereign Cloud
Microsoft Defender for Endpoint (and the Defender XDR portal) is reachable from the mainland — but on the ordinary global tenant Microsoft documents its endpoint telemetry resting in Azure data centers outside China (the EU, UK, US, Australia, Switzerland, India or the UAE — none in the mainland), so collecting it from China endpoints is a PIPL cross-border transfer, with Cybersecurity Law Article 39 (formerly Article 37) residency for CII operators. The lawful in-country footing is the sovereign-cloud pattern — Microsoft 365 operated by 21Vianet (世纪互联), which keeps data within China — but whether Defender's endpoint/XDR capabilities are available there is a feature-parity question to confirm with Microsoft and 21Vianet. A compliance-first look at where endpoint telemetry lives, the cross-border and residency questions, and the lawful in-country path.
Does Microsoft Defender work in China?
Reaching the Microsoft Defender portal from the mainland isn't the problem — where Defender for Endpoint keeps your China machines' telemetry is. This is about Microsoft Defender for Endpoint and the Defender XDR portal (the endpoint EDR product), not Defender for Cloud or Defender for Office 365.
Microsoft documents Defender for Endpoint operating in Azure data centers in the EU, UK, US, Australia, Switzerland, India or the UAE — none in mainland China — so on the ordinary global tenant the file, process, registry, network and device-identifier data it collects from your China endpoints rests offshore. That makes its collection a cross-border transfer under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–43), with an in-country storage duty for a CII operator under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37); larger or sensitive transfers can add a CAC data-export security assessment. The lawful in-country footing is the sovereign-cloud pattern, Microsoft 365 operated by 21Vianet, which keeps data within China — but whether Defender's endpoint/XDR capabilities are available there is a feature-parity question to confirm with Microsoft and 21Vianet.
21YunBox maps where your endpoint telemetry lives and your PIPL and residency exposure, localizes it onto an in-country footing, and delivers the China-facing Defender consoles and portals in-country on ICP-filed infrastructure — with no rebuild, and no circumvention of any kind. Treat the specifics as a risk to confirm with counsel.
What Microsoft Defender's own documentation says about China
| Fact | Primary source |
|---|---|
| Microsoft Defender for Endpoint stores its telemetry in offshore Azure regions — none in mainland China. Microsoft's data-storage documentation states that “Defender for Endpoint (including Defender Vulnerability Management) operates in the Microsoft Azure data centers in the European Union, the United Kingdom, the United States, Australia, Switzerland, India, or the United Arab Emirates (UAE),” with each tenant's data kept in the geolocation fixed at provisioning. Mainland China is not in that list. | Microsoft Learn — Microsoft Defender for Endpoint data storage and privacy (learn.microsoft.com), updated 2026-06-14, retrieved 2026-10-09 |
| What Defender for Endpoint collects is personal information. Microsoft's own documentation lists the collected data as file data (names, sizes, hashes), process and registry data, network-connection data including host IP addresses and ports, and device details such as device identifiers, names and operating-system versions — a machine-level record tied to identifiable devices and the employees using them. | Microsoft Learn — Microsoft Defender for Endpoint data storage and privacy, “What are we collecting?” (learn.microsoft.com), updated 2026-06-14, retrieved 2026-10-09 |
| The in-country footing is the 21Vianet sovereign cloud — but Defender's coverage on it is not established. Microsoft's service description says 21Vianet “operates local Microsoft 365 data centers to provide the ability to use Microsoft 365 services while keeping data within China” and that “these services are subject to Chinese laws,” yet also that “there are some features that have not yet been enabled,” and its feature tables list advanced threat-protection, threat-intelligence and Secure Score as not available in the China plans — so Defender endpoint/XDR coverage must be confirmed with Microsoft and 21Vianet. | Microsoft Learn — Microsoft 365 operated by 21Vianet, service description (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-09 |
| Exporting China endpoint telemetry to an offshore tenant is a PIPL cross-border transfer, with residency duties on top. Moving personal information collected from devices in mainland China to a Defender tenant hosted outside the country triggers PIPL Articles 38–43 (notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification), with in-country storage under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) for CII operators. | Personal Information Protection Law of the PRC, Chapter III, Articles 38–43 (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a mainland-China audience, the first thing to settle about Microsoft Defender is not whether the portal opens or how fast an alert surfaces — it is what Defender quietly carries off every machine it protects, and where that record comes to rest. This page is about a specific product: Microsoft Defender for Endpoint, the endpoint detection-and-response service, and the Microsoft Defender (XDR) portal that unifies it. That is a different thing from Microsoft Defender for Cloud, which guards Azure workloads, and from Microsoft Defender for Office 365, which filters email — and the distinction matters, because each has its own China footing. Defender for Endpoint is the one that installs a sensor on laptops, servers and phones and streams their activity to Microsoft.
What it streams is the point. Microsoft’s own documentation says Defender for Endpoint collects file, process and registry data, network-connection data including host IP addresses, and device details such as device identifiers, names and operating-system versions — a running, machine-level record of your workforce’s endpoints. Nearly all of it is personal information under Chinese law, tied to identifiable devices and the people using them. So the real question is not “can the Defender portal load from Shanghai?” — it can — but which tenant that endpoint telemetry lands in, and whether you had a lawful basis to collect and export it. That is a data-residency and cross-border question, and it sits upstream of performance.
Microsoft Defender in China at a glance
| What decides it | In Microsoft's own terms — and China's law |
|---|---|
| Which Defender this is | Microsoft Defender for Endpoint — the endpoint EDR sensor — and the Microsoft Defender (XDR) portal that unifies it. It collects file, process, registry, network-connection (host IPs and ports) and device-identifier data from your machines. Distinct from Defender for Cloud (Azure workloads) and Defender for Office 365 (email); each has its own China footing. |
| Is it reachable from the mainland? | Reaching the Defender portal and onboarding endpoints is not the obstacle. The China question is where the endpoint telemetry comes to rest and whether you may collect and export it — not load time. |
| Where the endpoint telemetry lives | On the global tenant, Microsoft documents the data in Azure data centers in the European Union, the United Kingdom, the United States, Australia, Switzerland, India or the UAE — none in mainland China. So the machine-level record of what your China endpoints did sits offshore. |
| Cross-border & residency | Collecting China endpoint telemetry into an offshore tenant is a cross-border transfer under PIPL (Articles 38–43: notice, a separate consent, one transfer mechanism). For a critical information infrastructure operator, in-country storage is required under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37); larger-volume or sensitive transfers can add a CAC data-export security assessment. |
| The in-country footing — and its Defender question | The sovereign-cloud pattern, Microsoft 365 operated by 21Vianet (世纪互联), keeps data within China. But Microsoft's own service description lists advanced threat-protection, threat-intelligence and Secure Score features as not available in the China plans and notes "some features that have not yet been enabled," so whether Defender's endpoint/XDR capabilities ride on the China cloud is a feature-parity question to confirm with Microsoft and 21Vianet. |
| The lawful path | Keep China endpoint telemetry in-country — on the 21Vianet-operated footing where Defender coverage exists, or a China-resident endpoint-security and telemetry arrangement where it does not — and deliver the China-facing Defender management and portals on ICP-filed, in-country infrastructure. 21YunBox maps the choice, localizes onto the in-country footing, and delivers it — no rebuild, no re-platform. |
Which Defender — and where its endpoint telemetry lives
Defender’s China posture is set in Microsoft’s documentation, not by a load-time test, and it is worth being exact about which Defender is in view. Microsoft Defender for Endpoint places a sensor on each device and streams its activity to a customer-dedicated tenant in the Microsoft cloud; the Defender (XDR) portal is where that signal is investigated. Microsoft’s data-storage documentation describes the collection plainly — file, process and registry data, network-connection data including host IP addresses and ports, and device details such as device identifiers, names and operating-system versions. Read against Chinese law, that is a continuous feed of personal information about identifiable machines and the employees behind them.
The location of that feed is documented just as plainly. Microsoft states that Defender for Endpoint “operates in the Microsoft Azure data centers in the European Union, the United Kingdom, the United States, Australia, Switzerland, India, or the United Arab Emirates (UAE),” with each tenant’s data kept in the geolocation fixed at provisioning. Mainland China is not one of those regions. So on the ordinary global tenant most organizations run, the endpoint telemetry Defender gathers from your China devices is stored outside the country by design — and that placement, not the portal’s responsiveness, is what the China decision turns on. For that reason this page publishes no first-party China latency figure for Defender: speed is not the axis here.
The cross-border story: endpoint telemetry is personal information
The gate that actually decides a China Defender for Endpoint deployment is the data. The sensor’s output identifies devices and, through host names, user-scoped file paths and network records, the people who use them — so when that telemetry is collected from machines in China into a tenant hosted in the EU, UK, US or any of the other offshore regions Microsoft lists, personal information has left the mainland. Under China’s Personal Information Protection Law that is a cross-border transfer, and the duty falls on the handler — you, the organization running Defender, not Microsoft as the processor. PIPL Chapter III (Articles 38–43) requires notice, a separate consent distinct from any general IT or employment agreement, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification.
Beneath consent sits residency. A critical information infrastructure operator, or a handler moving personal information at volume, must store personal information collected in China inside the mainland — PIPL Article 40, together with Cybersecurity Law Article 39 (formerly Article 37), the data-localization article renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged. An offshore Defender tenant structurally cannot meet that duty. And where the volume or sensitivity of the exported telemetry crosses the thresholds, the transfer itself can require a CAC data-export security assessment before it proceeds. How heavily each of these bites scales with your data, your sector and your role as handler, so treat it as a risk to confirm with counsel against what Defender actually collects in your environment — not a blanket assumption.
The data-resident footing: the 21Vianet sovereign cloud — and its Defender feature question
There is a lawful in-country footing for Microsoft’s cloud in China, and it is the one Microsoft already documents: the sovereign-cloud pattern, Microsoft 365 operated by 21Vianet (世纪互联). Microsoft’s service description states that 21Vianet “operates local Microsoft 365 data centers to provide the ability to use Microsoft 365 services while keeping data within China,” and that “these services are subject to Chinese laws.” That is the data-resident shape a China security posture is built on — a physically separate service, operated inside the mainland by a licensed local operator, with data kept in-country.
The honest caveat is specific to Defender. Riding on that footing is not automatic for endpoint protection, and Microsoft’s own documentation is the reason to check rather than assume. The 21Vianet service description states that, because of “the unique nature of the China services,” “there are some features that have not yet been enabled,” with parity improving over time — and its feature tables list advanced threat-protection, threat-intelligence and Secure Score capabilities as not available in the China plans. There is no separately documented “Defender for Endpoint operated by 21Vianet” service matching the global one. So the first step is not a migration but an availability-and-parity check: confirming directly with Microsoft and 21Vianet whether the specific Defender for Endpoint and Defender XDR capabilities your security team relies on are offered on the China cloud, and in what form. Where they are, the data-resident footing carries them. Where they are not, keeping China endpoint telemetry in-country means standing up a China-resident endpoint-security and telemetry arrangement for those devices, rather than streaming their signal offshore — a decision that is legal before it is technical.
The lawful path — and where 21YunBox fits (map, localize, deliver)
There is a lawful way to run endpoint security for a China workforce, and its shape is clear: the endpoint telemetry stays in-country, and the China-facing consoles, agents and portals that manage it are themselves delivered compliantly inside the mainland. That second half is easy to miss. A management portal, an onboarding page, or an internal security dashboard served to administrators in China is a public-facing service in the mainland, so it carries an ICP filing (备案) duty and needs compliant in-country delivery like any other China property — a console that authenticates instantly but hangs off an unfiled, offshore front end has solved only half the problem.
That is the footing 21YunBox owns, and it is more than advice. Our China team does three things on it. We map which Defender you are running, where its endpoint telemetry rests, and the PIPL cross-border, residency and data-export exposure that attaches to it — so you know what each option obliges before you commit. We localize your endpoint-security posture onto a data-resident footing — using the 21Vianet-operated path where Defender coverage exists, or standing up a China-resident endpoint-security and telemetry arrangement where it does not — in place of a global tenant that cannot meet the residency duty. And we deliver the China-facing Defender management surfaces and portals in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is an endpoint-security deployment that runs legally and compliantly for your users in China. What we never do is route anyone around anyone’s terms or around China’s network controls: this is a lawful, in-country deployment, and we neither use nor suggest circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — Article 39 (formerly Article 37) and data localization
- China’s data-export security assessment measures
- How to get an ICP filing for China
