{"data":{"id":"entra-admin","name":"Microsoft Entra sign-in and admin","summary":"Sign in to Microsoft Entra ID, use the Entra admin center and Microsoft Graph, and register security info for MFA.","scenario":"Admin workstation","products":["entra","graph"],"lastReviewed":"2026-10-06","m365SetIds":[56,59,84,125],"endpointVersion":"2026081400","missingSetIds":[],"references":[{"url":"https://learn.microsoft.com/en-us/entra/fundamentals/faq#how-can-i-allow-microsoft-entra-admin-center-urls-on-my-firewall-or-proxy-server-","title":"Microsoft Entra FAQ: allow Microsoft Entra admin center URLs on your firewall or proxy server"},{"url":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","title":"Microsoft 365 URLs and IP address ranges: Microsoft 365 Common and Office Online"}],"notes":"Sets 56 and 59 are the Microsoft 365 identity sets; 84 and 125 cover certificate revocation. The Entra FAQ publishes *.entra.microsoft.com and points to the Azure portal safelist, so the portal framework hosts are included; Microsoft does not document which of them the Entra admin center actually calls.","entries":[{"destination":"login.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra sign-in and token endpoint","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56. Also listed by the Azure portal safelist and the Microsoft Entra hybrid join network requirements."},{"destination":"login.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra sign-in endpoint","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"login.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Legacy Microsoft Entra sign-in endpoint","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"device.login.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Device-based authentication for device Conditional Access","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join#network-connectivity-requirements","sourceTitle":"Configure Microsoft Entra hybrid join","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Also endpoint set 56. The page says to exclude it from TLS break-and-inspect."},{"destination":"enterpriseregistration.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Device registration for Microsoft Entra join, hybrid join and device Conditional Access","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join#network-connectivity-requirements","sourceTitle":"Configure Microsoft Entra hybrid join","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Also endpoint set 59. Exclude from TLS inspection per the same page."},{"destination":"autologon.microsoftazuread-sso.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Seamless single sign-on","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join#network-connectivity-requirements","sourceTitle":"Configure Microsoft Entra hybrid join","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Only if you use seamless SSO. Also endpoint set 56."},{"destination":"*.msftauth.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Sign-in page content delivery","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Endpoint set 59. Covers the narrower *.aadcdn.msftauth.net and *.logincdn.msftauth.net listed by the Azure portal safelist."},{"destination":"*.msauth.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Sign-in page content delivery","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Endpoint set 59."},{"destination":"*.msftauthimages.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Sign-in company branding images","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Endpoint set 59."},{"destination":"*.msauthimages.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Sign-in company branding images","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Endpoint set 59."},{"destination":"*.microsoftonline.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra identity service hosts","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Endpoint set 59; set 56 lists the specific hosts."},{"destination":"*.microsoftonline-p.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Legacy identity and sign-in content delivery","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":"Endpoint set 59; also on the Azure portal safelist."},{"destination":"*.auth.microsoft.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra authentication services, including multifactor authentication","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"*.msidentity.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra identity service","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"*.msftidentity.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra identity service","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"graph.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Graph, used by the admin centers and admin tools","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"graph.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Legacy Azure AD Graph","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56. Azure AD Graph is retiring but is still published as required."},{"destination":"account.activedirectory.windowsazure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Legacy multifactor authentication and access panel endpoint","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56 (required within the set)."},{"destination":"passwordreset.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Self-service password reset","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"api.passwordreset.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Self-service password reset API","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":"Endpoint set 56."},{"destination":"*.entra.microsoft.com","kind":"WildcardFqdn","protocol":"TCP","ports":[443],"purpose":"Microsoft Entra admin center","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/entra/fundamentals/faq#how-can-i-allow-microsoft-entra-admin-center-urls-on-my-firewall-or-proxy-server-","sourceTitle":"Frequently asked questions about Microsoft Entra","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"The FAQ also says to include the Azure portal safelist URLs. No port stated; HTTPS assumed."},{"destination":"entra.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[443],"purpose":"Microsoft Entra admin center address","required":true,"origin":"Curated","reason":"The FAQ publishes only *.entra.microsoft.com, which doesn't match the admin center's own address; the Azure portal safelist advises adding the bare domain next to each wildcard.","sourceUrl":"https://learn.microsoft.com/en-us/entra/fundamentals/faq#how-can-i-allow-microsoft-entra-admin-center-urls-on-my-firewall-or-proxy-server-","sourceTitle":"Frequently asked questions about Microsoft Entra","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"portal.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal address used by Entra admin center links","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.portal.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal framework shared by the Entra admin center","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Included because the Entra FAQ points to the Azure portal safelist; Microsoft doesn't document which framework hosts the Entra admin center uses."},{"destination":"*.hosting.portal.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal extension hosting","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Undetermined","acquisitionConfidence":"Possible","acquisitionBasis":"Broader than the Microsoft 365 entries it includes (such as set 73): those parts are expected to go to a Microsoft profile and the rest to Internet Access.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"hosting.portal.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal extension hosting (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.hosting.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.hosting-ms.portal.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal extension hosting","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"hosting-ms.portal.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal extension hosting (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.hosting-ms.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.reactblade.portal.azure.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal React blades","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"reactblade.portal.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal React blades (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.reactblade.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"management.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure Resource Manager, part of the portal framework","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.ext.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal extension services","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"ext.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal extension services (bare domain)","required":true,"origin":"Curated","reason":"Bare-domain companion of *.ext.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"*.graph.microsoft.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Graph subdomains used by the portal framework","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"Doesn't match graph.microsoft.com itself, which is listed separately."},{"destination":"*.graph.windows.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure AD Graph subdomains used by the portal framework","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"hosting.partners.azure.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Azure portal partner extension hosting","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"login.live.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft account sign-in","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":97,"placeholders":[],"notes":"Only for Microsoft account or guest scenarios; also optional endpoint sets 97 and 116."},{"destination":"mspim.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Privileged Identity Management","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Labelled Microsoft Entra on the page; relevant when admins activate roles with PIM."},{"destination":"api.azrbac.mspim.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Privileged Identity Management API","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Labelled Microsoft Entra on the page."},{"destination":"*.aad.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra portal services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Labelled Microsoft Entra on the page."},{"destination":"aad.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra portal services (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.aad.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"ad.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra portal services","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Labelled Microsoft Entra on the page."},{"destination":"appmanagement.activedirectory.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra application management","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"Labelled Microsoft Entra on the page."},{"destination":"*.aadconnecthealth.azure.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra Connect Health portal","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"Labelled Microsoft Entra on the page."},{"destination":"aadconnecthealth.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra Connect Health portal (bare domain)","required":false,"origin":"Curated","reason":"Bare-domain companion of *.aadconnecthealth.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'","sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":null},{"destination":"identitygovernance.azure.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft Entra ID Governance","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation","sourceTitle":"Allow the Azure portal URLs on your firewall or proxy server","acquisition":"InternetAccess","acquisitionConfidence":"Likely","acquisitionBasis":"Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.","expectedAtWebFiltering":true,"m365SetId":null,"placeholders":[],"notes":"The same section also lists iga.azure.com and elm.iga.azure.com."},{"destination":"mysignins.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[443],"purpose":"My Sign-ins and Security info, including MFA registration","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#switch-directory","sourceTitle":"Combined registration for SSPR and Microsoft Entra multifactor authentication","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"Appears in the page's https://mysignins.microsoft.com/security-info links. Not in the Microsoft 365 endpoint list except under the optional *.microsoft.com wildcard."},{"destination":"myaccount.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[443],"purpose":"My Account portal","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#set-up-security-info-from-my-account","sourceTitle":"Combined registration for SSPR and Microsoft Entra multifactor authentication","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":null,"placeholders":[],"notes":"Not in the Microsoft 365 endpoint list except under the optional *.microsoft.com wildcard."},{"destination":"aka.ms","kind":"Fqdn","protocol":"TCP","ports":[443],"purpose":"Microsoft short links such as aka.ms/mysecurityinfo","required":false,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-teams","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":17,"placeholders":[],"notes":"Endpoint set 17."},{"destination":"crl.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Certificate revocation lists","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":84,"placeholders":[],"notes":"Endpoint set 84. Revocation checks use plain HTTP on port 80."},{"destination":"oneocsp.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"OCSP for Microsoft certificates","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":"Endpoint set 125, which also lists the third-party CA revocation hosts merged from the live list."},{"destination":"ocsp.msocsp.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"OCSP for Microsoft certificates","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":"Endpoint set 125."},{"destination":"mscrl.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Microsoft certificate revocation list distribution","required":true,"origin":"Published","reason":null,"sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online","sourceTitle":"Microsoft 365 URLs and IP address ranges","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":"Endpoint set 125."},{"destination":"accounts.accesscontrol.windows.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"adminwebservice.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"becws.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"ccs.login.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"clientconfig.microsoftonline-p.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"companymanager.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"login-us.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"login.microsoftonline-p.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"logincert.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"loginex.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"nexus.microsoftonline-p.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"provisioningapi.microsoftonline.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"20.190.128.0/18","kind":"Ipv4Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"20.20.32.0/19","kind":"Ipv4Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"20.231.128.0/19","kind":"Ipv4Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1006:2000::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1007:200::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1016:1400::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1017::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1026:3000::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1027:1::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1036:3000::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1037:1::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1046:2000::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1047:1::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1056:2000::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"2603:1057:2::/48","kind":"Ipv6Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"40.126.0.0/18","kind":"Ipv4Cidr","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 56 (Allow)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 56","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":56,"placeholders":[],"notes":null},{"destination":"*.hip.live.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 59 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 59","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":null},{"destination":"*.msecnd.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 59 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 59","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":null},{"destination":"*.phonefactor.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 59 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 59","acquisition":"EntraSystem","acquisitionConfidence":"Likely","acquisitionBasis":"In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.","expectedAtWebFiltering":false,"m365SetId":59,"placeholders":[],"notes":null},{"destination":"*.entrust.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.geotrust.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.omniroot.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.public-trust.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.symcb.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.symcd.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.verisign.com","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"*.verisign.net","kind":"WildcardFqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"cacerts.digicert.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"cert.int-x3.letsencrypt.org","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"crl.globalsign.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"crl.globalsign.net","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"crl.identrust.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"crl3.digicert.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"crl4.digicert.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"isrg.trustid.ocsp.identrust.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"ocsp.digicert.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"ocsp.globalsign.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"ocsp2.globalsign.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"ocspx.digicert.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"secure.globalsign.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"www.digicert.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null},{"destination":"www.microsoft.com","kind":"Fqdn","protocol":"TCP","ports":[80,443],"purpose":"Common endpoint set 125 (Default)","required":true,"origin":"Published","reason":null,"sourceUrl":"https://endpoints.office.com/endpoints/Worldwide","sourceTitle":"Microsoft 365 endpoint web service, Worldwide version 2026081400, set 125","acquisition":"Microsoft365","acquisitionConfidence":"Possible","acquisitionBasis":"In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.","expectedAtWebFiltering":null,"m365SetId":125,"placeholders":[],"notes":null}],"evidence":{"confidence":"Current","sources":[{"sourceId":"m365-endpoints-worldwide","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.692576+00:00"}],"note":null}},"metadata":{"apiVersion":"1","snapshotId":"8262706f51794f7db21e8bd3f982b386","refreshedAt":"2026-10-07T05:10:36.5571664+00:00","observingSince":"2026-09-26T17:11:44.4078421+00:00","evaluatedAt":"2026-10-07T05:19:14.0664092+00:00","evidence":{"confidence":"Current","sources":[{"sourceId":"windows-itpro","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-security-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-365-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"exchange-team-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"intune-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-xdr-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-server-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"powershell-team-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-security-blog-main","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"teams-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sharepoint-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-cloud-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sentinel-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"avd-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-arc-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"configmgr-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sql-server-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"onedrive-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"fabric-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"powerbi-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"power-platform-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-governance-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"core-infrastructure-security-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"askds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"itops-talk-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sysinternals-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-insider-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-experience-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"security-baselines-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-infrastructure-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-365-developer-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"purview-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-identity-platform-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-devops-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jamf-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jamf-status-history","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"oracle-security-alerts","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"cloudflare-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"openai-news","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"google-gemini-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"evotec-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"office365itpros","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"oofhours","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"msendpointmgr","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"andrewstaylor","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jeffreyappel","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"askwoody","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"borncity","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"petri","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"patchmypc","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dynamics-365-product-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"practical365","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"call4cloud","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dirteam-sander","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"chrisse","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dotnet-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jan-bakker","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"adsecurity","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"maester-blog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-news","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"nathan-mcnulty","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"graph-changelog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"msrc-security-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"msrc-cvrf","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"cisa-kev","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"first-epss","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"public-exploit-code","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-365-roadmap","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"microsoft-lifecycle","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"edge-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"m365-apps-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"teams-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-updates","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"exchange-builds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sharepoint-builds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sql-server-builds","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dotnet-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-admx","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"graph-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"az-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"psresourceget-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"psreadline-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-cli-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-terminal-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"winget-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"vscode-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"exchange-online-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"teams-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"chrome-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"firefox-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"apple-security-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"oracle-java-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"jamf-pro-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"android-security-bulletins","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"vmware-esxi-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"vmware-vcenter-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pnp-powershell-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pester-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dbatools-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"maester-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"adessentials-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"gpozaurr-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"testimo-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"mailozaurr-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pswritehtml-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pswriteoffice-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"psparsehtml-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pspublishmodule-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"pseventviewer-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"dnsclientx-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"cleanupmonster-versions","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"openai-models","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"anthropic-models","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"gemini-models","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-client-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-macos-client-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-connector-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"global-secure-access-sensor-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-android-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-ios-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-windows-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-macos-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-endpoint-linux-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"intune-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"entra-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-xdr-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"purview-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-identity-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-office-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-cloud-apps-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"defender-cloud-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"sentinel-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-365-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"avd-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"copilot-studio-whats-new","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-arc-agent-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"openai-api-changelog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"claude-release-notes","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"gemini-api-changelog","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-message-center","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-11-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-10-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"windows-server-releases","confidence":"Current","lastReadAt":"2026-10-07T05:10:36.5571664+00:00"},{"sourceId":"azure-service-tags-public","confidence":"Current","lastReadAt":"2026-10-06T08:00:54.1096255+00:00"},{"sourceId":"m365-endpoints-worldwide","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.692576+00:00"},{"sourceId":"outlook-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6927646+00:00"},{"sourceId":"excel-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928023+00:00"},{"sourceId":"graph-known-issues","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928251+00:00"},{"sourceId":"identity-breaking-changes","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928362+00:00"},{"sourceId":"powershell-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6928574+00:00"},{"sourceId":"graph-powershell-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.692893+00:00"},{"sourceId":"azure-cli-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6929108+00:00"},{"sourceId":"azure-public-incidents","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6929236+00:00"},{"sourceId":"azure-incident-reviews","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6930439+00:00"},{"sourceId":"security-baseline-artifacts","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6930828+00:00"},{"sourceId":"entra-connect-releases","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6931216+00:00"},{"sourceId":"intune-notices","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521163+00:00"},{"sourceId":"intune-in-development","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521393+00:00"},{"sourceId":"autopilot-whats-new","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521479+00:00"},{"sourceId":"autopilot-preparation-whats-new","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521673+00:00"},{"sourceId":"windows-365-enterprise-known-issues","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2521731+00:00"},{"sourceId":"windows-365-business-known-issues","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2526882+00:00"},{"sourceId":"fabric-whats-new","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2527703+00:00"},{"sourceId":"windows-server-feature-deprecations","confidence":"Current","lastReadAt":"2026-10-07T01:05:54.6161314+00:00"},{"sourceId":"learn-toc-global-secure-access","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8566792+00:00"},{"sourceId":"learn-toc-intune","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8586908+00:00"},{"sourceId":"learn-toc-entra-conditional-access","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8587896+00:00"},{"sourceId":"learn-toc-entra-authentication","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8588521+00:00"},{"sourceId":"learn-toc-defender-endpoint","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.858887+00:00"},{"sourceId":"learn-toc-windows-deployment","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8589176+00:00"},{"sourceId":"learn-toc-windows-client-management","confidence":"Current","lastReadAt":"2026-10-06T16:26:11.8589415+00:00"},{"sourceId":"vmware-security-advisories","confidence":"Current","lastReadAt":"2026-10-07T05:09:35.6931636+00:00"},{"sourceId":"product-terms-feed","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2528034+00:00"},{"sourceId":"product-terms-mca","confidence":"Current","lastReadAt":"2026-10-07T00:04:56.2529033+00:00"},{"sourceId":"partner-announcements","confidence":"Current","lastReadAt":"2026-10-06T23:03:56.4694574+00:00"}],"note":null}}}