{"data":{"id":"azure-portal","name":"Azure portal","summary":"The Azure portal safelist for the public cloud: authentication, the portal framework, account data, and optional per-service hosts.","scenario":"Admin workstation","products":["azure"],"lastReviewed":"2026-10-06","m365SetIds":[],"endpointVersion":"2026081400","missingSetIds":[],"references":[{"url":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","title":"Allow the Azure portal URLs on your firewall or proxy server"},{"url":"https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview","title":"Azure service tags (AzureActiveDirectory, AzureResourceManager, AzureFrontDoor.Frontend, AzureFrontDoor.FirstParty)"}],"notes":"Microsoft says to allow both a wildcard and its bare domain but spells out only portal.azure.com; every other bare domain here is a Curated companion of a listed wildcard and follows that advice. The general services section is optional and depends on the services you use. Traffic to these endpoints uses TCP ports 80 and 443.","entries":[{"destination":"portal.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Portal apex (non-wildcard companion of *.portal.azure.com)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Named in the Important note: 'add both *.portal.azure.com and portal.azure.com'. The note also says to add the bare domain for every wildcard entry; portal.azure.com is the only one it spells out, so the others are Curated entries next to their wildcards."},{"destination":"login.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"login.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"login.live.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":97,"placeholders":[],"notes":null},{"destination":"*.aadcdn.msftauth.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (sign-in CDN)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aadcdn.msftauth.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (sign-in CDN) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.aadcdn.msftauth.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.aadcdn.msftauthimages.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (branding images CDN)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aadcdn.msftauthimages.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (branding images CDN) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.aadcdn.msftauthimages.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.aadcdn.msauthimages.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (branding images CDN)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aadcdn.msauthimages.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (branding images CDN) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.aadcdn.msauthimages.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.logincdn.msftauth.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (login CDN)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"logincdn.msftauth.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (login CDN) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.logincdn.msftauth.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.msauth.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":null},{"destination":"msauth.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.msauth.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.aadcdn.microsoftonline-p.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aadcdn.microsoftonline-p.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.aadcdn.microsoftonline-p.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.microsoftonline-p.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"The page adds that you may also need authentication URLs from sections 56, 59 and 97 of the Microsoft 365 URLs and IP address ranges list."},{"destination":"microsoftonline-p.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal authentication (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.microsoftonline-p.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.portal.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.hosting.portal.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (extension hosting)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Undetermined","acquisitionConfidence":"Possible","acquisitionBasis":"Broader than the Microsoft 365 entries it includes (such as set 73): those parts are expected to go to a Microsoft profile and the rest to Internet Access.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"hosting.portal.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (extension hosting) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.hosting.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.hosting-ms.portal.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (extension hosting)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"hosting-ms.portal.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (extension hosting) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.hosting-ms.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.reactblade.portal.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (React blades)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"reactblade.portal.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (React blades) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.reactblade.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"management.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (Azure Resource Manager)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.ext.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (extensions)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"ext.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (extensions) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.ext.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.graph.windows.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (Azure AD Graph)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"graph.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (Azure AD Graph) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.graph.windows.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"*.graph.microsoft.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (Microsoft Graph)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"The bare graph.microsoft.com is not listed here; it follows as a Curated entry under the page's own advice."},{"destination":"graph.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (Microsoft Graph) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.graph.microsoft.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"hosting.partners.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework (partner extension hosting)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.account.microsoft.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"The page doesn't say whether Account data is mandatory. I set required=true because it is a portal-core section, not a per-service one."},{"destination":"account.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.account.microsoft.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.bmx.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"bmx.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.bmx.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.subscriptionrp.trafficmanager.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data (subscriptions)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"subscriptionrp.trafficmanager.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data (subscriptions) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.subscriptionrp.trafficmanager.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.signup.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data (sign-up)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"signup.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Account data (sign-up) (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.signup.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aka.ms","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft short URL","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":17,"placeholders":[],"notes":"General services section: the page says you may not need all of these, depending on the services you use."},{"destination":"*.asazure.windows.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Analysis Services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.azconfig.io","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"AzConfig Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"azconfig.io","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"AzConfig Service (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.azconfig.io. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.aad.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aad.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.aad.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.aadconnecthealth.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"aadconnecthealth.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.aadconnecthealth.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"ad.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"adf.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Data Factory","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"api.aadrm.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 73 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"api.loganalytics.io","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Log Analytics Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"api.azrbac.mspim.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra (PIM)","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Relevant to privileged admins who use PIM."},{"destination":"*.applicationinsights.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Application Insights Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"applicationinsights.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Application Insights Service (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.applicationinsights.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"appmanagement.activedirectory.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"appservice.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure App Services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.arc.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Arc","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"arc.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Arc (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.arc.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"asazure.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Analysis Services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"bastion.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Bastion Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"batch.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Batch Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"catalogapi.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Marketplace","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"catalogartifact.azureedge.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Marketplace","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"changeanalysis.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Change Analysis","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"cognitiveservices.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Cognitive Services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"config.office.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Office","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"cosmos.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Cosmos DB","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.database.windows.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"SQL Server","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Portal access only; direct SQL connections (TCP 1433) are out of scope for this page."},{"destination":"database.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"SQL Server (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.database.windows.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"datalake.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Data Lake Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"dev.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure DevOps","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"dev.azuresynapse.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Synapse","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"digitaltwins.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Digital Twins","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"elm.iga.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra (entitlement management)","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"eventhubs.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Event Hubs","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"functions.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Functions","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"gallery.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Marketplace","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"go.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft documentation placeholder","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":89,"placeholders":[],"notes":null},{"destination":"help.kusto.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Kusto Cluster Help","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"identitygovernance.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"iga.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"informationprotection.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"kusto.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Kusto Clusters","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"learn.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure documentation","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"logic.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Logic Apps","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"marketplacedataprovider.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Marketplace","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"main.prod.marketplacedataprovider.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Marketplace","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"marketplaceemail.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Marketplace","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"media.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Media Services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"monitor.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Monitor Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.msidentity.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"msidentity.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.msidentity.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"mspim.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra (PIM)","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Relevant to privileged admins who use PIM."},{"destination":"network.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Network","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"purview.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Purview","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"quantum.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Quantum Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"rest.media.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Media Services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"search.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Search","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"servicebus.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Service Bus","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"servicebus.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Service Bus","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"shell.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Command Shell","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"sphere.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Sphere","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"azure.status.microsoft","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Status","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"storage.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Storage","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"storage.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Storage","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"vault.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Key Vault Service","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Listed as the bare name only, not *.vault.azure.net."},{"destination":"ux.console.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Cloud Shell","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null}],"evidence":{"confidence":"Current","sources":[],"note":null}},"metadata":{"apiVersion":"1","snapshotId":"8262706f51794f7db21e8bd3f982b386","refreshedAt":"2026-10-07T05:10:36.5571664+00:00","observingSince":"2026-09-26T17:11:44.4078421+00:00","evaluatedAt":"2026-10-07T05:23:11.3364591+00:00","evidence":{"confidence":"Current","sources":[{"sourceId":"windows-itpro","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-security-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-365-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"exchange-team-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"intune-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-xdr-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-server-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"powershell-team-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-security-blog-main","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"teams-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sharepoint-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-cloud-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sentinel-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"avd-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-arc-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"configmgr-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sql-server-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"onedrive-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"fabric-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"powerbi-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"power-platform-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-governance-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"core-infrastructure-security-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"askds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"itops-talk-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sysinternals-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-insider-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-experience-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"security-baselines-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-infrastructure-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-365-developer-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"purview-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-identity-platform-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-devops-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jamf-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jamf-status-history","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"oracle-security-alerts","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"cloudflare-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"openai-news","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"google-gemini-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"evotec-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"office365itpros","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"oofhours","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"msendpointmgr","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"andrewstaylor","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jeffreyappel","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"askwoody","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"borncity","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"petri","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"patchmypc","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dynamics-365-product-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"practical365","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"call4cloud","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dirteam-sander","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"chrisse","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dotnet-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jan-bakker","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"adsecurity","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"maester-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-news","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"nathan-mcnulty","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"graph-changelog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"msrc-security-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"msrc-cvrf","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"cisa-kev","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"first-epss","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"public-exploit-code","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-365-roadmap","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-lifecycle","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"edge-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"m365-apps-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"teams-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"exchange-builds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sharepoint-builds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sql-server-builds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dotnet-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-admx","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"graph-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"az-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"psresourceget-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"psreadline-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-cli-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-terminal-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"winget-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"vscode-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"exchange-online-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"teams-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"chrome-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"firefox-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"apple-security-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"oracle-java-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jamf-pro-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"android-security-bulletins","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"vmware-esxi-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"vmware-vcenter-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pnp-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pester-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dbatools-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"maester-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"adessentials-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"gpozaurr-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"testimo-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"mailozaurr-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pswritehtml-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pswriteoffice-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"psparsehtml-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pspublishmodule-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pseventviewer-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dnsclientx-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"cleanupmonster-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"openai-models","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"anthropic-models","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"gemini-models","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-client-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-macos-client-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-connector-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-sensor-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-android-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-ios-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-windows-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-macos-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-linux-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"intune-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-xdr-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"purview-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-identity-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-office-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-cloud-apps-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-cloud-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sentinel-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-365-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"avd-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"copilot-studio-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-arc-agent-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"openai-api-changelog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"claude-release-notes","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"gemini-api-changelog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-message-center","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-11-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-10-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-server-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-service-tags-public","confidence":"Current","lastReadAt":"2026-10-06T08:00:54.1096255+00:00"},{"sourceId":"m365-endpoints-worldwide","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.692576+00:00"},{"sourceId":"outlook-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6927646+00:00"},{"sourceId":"excel-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928023+00:00"},{"sourceId":"graph-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928251+00:00"},{"sourceId":"identity-breaking-changes","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928362+00:00"},{"sourceId":"powershell-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928574+00:00"},{"sourceId":"graph-powershell-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.692893+00:00"},{"sourceId":"azure-cli-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6929108+00:00"},{"sourceId":"azure-public-incidents","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6929236+00:00"},{"sourceId":"azure-incident-reviews","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6930439+00:00"},{"sourceId":"security-baseline-artifacts","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6930828+00:00"},{"sourceId":"entra-connect-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6931216+00:00"},{"sourceId":"intune-notices","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521163+00:00"},{"sourceId":"intune-in-development","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521393+00:00"},{"sourceId":"autopilot-whats-new","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521479+00:00"},{"sourceId":"autopilot-preparation-whats-new","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521673+00:00"},{"sourceId":"windows-365-enterprise-known-issues","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521731+00:00"},{"sourceId":"windows-365-business-known-issues","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2526882+00:00"},{"sourceId":"fabric-whats-new","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2527703+00:00"},{"sourceId":"windows-server-feature-deprecations","confidence":"Current","lastReadAt":"2026-10-07T01:05:54.6161314+00:00"},{"sourceId":"learn-toc-global-secure-access","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8566792+00:00"},{"sourceId":"learn-toc-intune","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8586908+00:00"},{"sourceId":"learn-toc-entra-conditional-access","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8587896+00:00"},{"sourceId":"learn-toc-entra-authentication","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8588521+00:00"},{"sourceId":"learn-toc-defender-endpoint","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.858887+00:00"},{"sourceId":"learn-toc-windows-deployment","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8589176+00:00"},{"sourceId":"learn-toc-windows-client-management","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8589415+00:00"},{"sourceId":"vmware-security-advisories","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6931636+00:00"},{"sourceId":"product-terms-feed","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2528034+00:00"},{"sourceId":"product-terms-mca","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2529033+00:00"},{"sourceId":"partner-announcements","confidence":"Current","lastReadAt":"2026-10-06T23:03:56.4694574+00:00"}],"note":null}}}