182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Azure portal

The Azure portal safelist for the public cloud: authentication, the portal framework, account data, and optional per-service hosts.

Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Azure

Microsoft says to allow both a wildcard and its bare domain but spells out only portal.azure.com; every other bare domain here is a Curated companion of a listed wildcard and follows that advice. The general services section is optional and depends on the services you use. Traffic to these endpoints uses TCP ports 80 and 443.

Cited pages since the review

2 of 2 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data
FormatDestinationsLeft outDownload
Plain list, one per line1090 Open
GSA V1 domain list1090 Open
GSA V1 Graph request body1090 Download
GSA V2 rules (review JSON)1090 Download
GSA V2 rules (CSV)1090 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/azure-portal. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle azure-portal from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Expected to reach web filtering81expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
DestinationPortsPurposeEvidence
*.bmx.azure.com TCP 80, 443 Account data PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

bmx.azure.com TCP 80, 443 Account data (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.bmx.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.ext.azure.com TCP 80, 443 Azure portal framework (extensions) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

ext.azure.com TCP 80, 443 Azure portal framework (extensions) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.ext.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.graph.windows.net TCP 80, 443 Azure portal framework (Azure AD Graph) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.hosting-ms.portal.azure.net TCP 80, 443 Azure portal framework (extension hosting) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

hosting-ms.portal.azure.net TCP 80, 443 Azure portal framework (extension hosting) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.hosting-ms.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

hosting.partners.azure.net TCP 80, 443 Azure portal framework (partner extension hosting) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

hosting.portal.azure.net TCP 80, 443 Azure portal framework (extension hosting) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.hosting.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

management.azure.com TCP 80, 443 Azure portal framework (Azure Resource Manager) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

microsoftonline-p.com TCP 80, 443 Azure portal authentication (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.microsoftonline-p.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

msauth.net TCP 80, 443 Azure portal authentication (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.msauth.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

portal.azure.com TCP 80, 443 Portal apex (non-wildcard companion of *.portal.azure.com)Named in the Important note: 'add both *.portal.azure.com and portal.azure.com'. The note also says to add the bare domain for every wildcard entry; portal.azure.com is the only one it spells out, so the others are Curated entries next to their wildcards. PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.portal.azure.com TCP 80, 443 Azure portal framework PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.reactblade.portal.azure.net TCP 80, 443 Azure portal framework (React blades) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

reactblade.portal.azure.net TCP 80, 443 Azure portal framework (React blades) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.reactblade.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.signup.azure.com TCP 80, 443 Account data (sign-up) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

signup.azure.com TCP 80, 443 Account data (sign-up) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.signup.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.subscriptionrp.trafficmanager.net TCP 80, 443 Account data (subscriptions) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

subscriptionrp.trafficmanager.net TCP 80, 443 Account data (subscriptions) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.subscriptionrp.trafficmanager.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.aad.azure.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

aad.azure.comoptional TCP 80, 443 Microsoft Entra (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aad.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.aadconnecthealth.azure.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

aadconnecthealth.azure.comoptional TCP 80, 443 Microsoft Entra (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aadconnecthealth.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

ad.azure.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

adf.azure.comoptional TCP 80, 443 Azure Data Factory PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

api.azrbac.mspim.azure.comoptional TCP 80, 443 Microsoft Entra (PIM)Relevant to privileged admins who use PIM. PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

api.loganalytics.iooptional TCP 80, 443 Log Analytics Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.applicationinsights.azure.comoptional TCP 80, 443 Application Insights Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

applicationinsights.azure.comoptional TCP 80, 443 Application Insights Service (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.applicationinsights.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

appservice.azure.comoptional TCP 80, 443 Azure App Services PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.arc.azure.netoptional TCP 80, 443 Azure Arc PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

arc.azure.netoptional TCP 80, 443 Azure Arc (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.arc.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.asazure.windows.netoptional TCP 80, 443 Analysis Services PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

asazure.windows.netoptional TCP 80, 443 Analysis Services PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.azconfig.iooptional TCP 80, 443 AzConfig Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

azconfig.iooptional TCP 80, 443 AzConfig Service (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.azconfig.io. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

azure.status.microsoftoptional TCP 80, 443 Azure Status PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

bastion.azure.comoptional TCP 80, 443 Azure Bastion Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

batch.azure.comoptional TCP 80, 443 Azure Batch Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

catalogapi.azure.comoptional TCP 80, 443 Azure Marketplace PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

catalogartifact.azureedge.netoptional TCP 80, 443 Azure Marketplace PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

changeanalysis.azure.comoptional TCP 80, 443 Change Analysis PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

cognitiveservices.azure.comoptional TCP 80, 443 Cognitive Services PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

cosmos.azure.comoptional TCP 80, 443 Azure Cosmos DB PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.database.windows.netoptional TCP 80, 443 SQL ServerPortal access only; direct SQL connections (TCP 1433) are out of scope for this page. PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

database.windows.netoptional TCP 80, 443 SQL Server (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.database.windows.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

datalake.azure.netoptional TCP 80, 443 Azure Data Lake Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

dev.azure.comoptional TCP 80, 443 Azure DevOps PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

dev.azuresynapse.netoptional TCP 80, 443 Azure Synapse PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

digitaltwins.azure.netoptional TCP 80, 443 Azure Digital Twins PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

elm.iga.azure.comoptional TCP 80, 443 Microsoft Entra (entitlement management) PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

eventhubs.azure.netoptional TCP 80, 443 Azure Event Hubs PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

functions.azure.comoptional TCP 80, 443 Azure Functions PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

gallery.azure.comoptional TCP 80, 443 Azure Marketplace PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

help.kusto.windows.netoptional TCP 80, 443 Azure Kusto Cluster Help PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

identitygovernance.azure.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

iga.azure.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

informationprotection.azure.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

kusto.windows.netoptional TCP 80, 443 Azure Kusto Clusters PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

logic.azure.comoptional TCP 80, 443 Logic Apps PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

main.prod.marketplacedataprovider.azure.comoptional TCP 80, 443 Azure Marketplace PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

marketplacedataprovider.azure.comoptional TCP 80, 443 Azure Marketplace PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

marketplaceemail.azure.comoptional TCP 80, 443 Azure Marketplace PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

media.azure.netoptional TCP 80, 443 Azure Media Services PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

monitor.azure.comoptional TCP 80, 443 Azure Monitor Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

msidentity.comoptional TCP 80, 443 Microsoft Entra (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.msidentity.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

mspim.azure.comoptional TCP 80, 443 Microsoft Entra (PIM)Relevant to privileged admins who use PIM. PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

network.azure.comoptional TCP 80, 443 Azure Network PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

purview.azure.comoptional TCP 80, 443 Azure Purview PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

quantum.azure.comoptional TCP 80, 443 Azure Quantum Service PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

rest.media.azure.netoptional TCP 80, 443 Azure Media Services PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

search.azure.comoptional TCP 80, 443 Azure Search PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

servicebus.azure.netoptional TCP 80, 443 Azure Service Bus PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

servicebus.windows.netoptional TCP 80, 443 Azure Service Bus PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

shell.azure.comoptional TCP 80, 443 Azure Command Shell PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

sphere.azure.netoptional TCP 80, 443 Azure Sphere PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

storage.azure.comoptional TCP 80, 443 Azure Storage PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

storage.azure.netoptional TCP 80, 443 Azure Storage PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

ux.console.azure.comoptional TCP 80, 443 Azure Cloud Shell PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

vault.azure.netoptional TCP 80, 443 Azure Key Vault ServiceListed as the bare name only, not *.vault.azure.net. PublishedAllow the Azure portal URLs on your firewall or proxy server
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

Not determined13public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
*.account.microsoft.com TCP 80, 443 Account dataThe page doesn't say whether Account data is mandatory. I set required=true because it is a portal-core section, not a per-service one. PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

account.microsoft.com TCP 80, 443 Account data (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.account.microsoft.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.graph.microsoft.com TCP 80, 443 Azure portal framework (Microsoft Graph)The bare graph.microsoft.com is not listed here; it follows as a Curated entry under the page's own advice. PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

graph.microsoft.com TCP 80, 443 Azure portal framework (Microsoft Graph) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy server · set 56Bare-domain companion of *.graph.microsoft.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.hosting.portal.azure.net TCP 80, 443 Azure portal framework (extension hosting) PublishedAllow the Azure portal URLs on your firewall or proxy server
Not determined · possible, not confirmed

Broader than the Microsoft 365 entries it includes (such as set 73): those parts are expected to go to a Microsoft profile and the rest to Internet Access.

login.live.com TCP 80, 443 Azure portal authentication PublishedAllow the Azure portal URLs on your firewall or proxy server · set 97
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

login.microsoft.com TCP 80, 443 Azure portal authentication PublishedAllow the Azure portal URLs on your firewall or proxy server · set 56
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

aka.msoptional TCP 80, 443 Microsoft short URLGeneral services section: the page says you may not need all of these, depending on the services you use. PublishedAllow the Azure portal URLs on your firewall or proxy server · set 17
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

api.aadrm.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 73 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

appmanagement.activedirectory.microsoft.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

config.office.comoptional TCP 80, 443 Microsoft Office PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

go.microsoft.comoptional TCP 80, 443 Microsoft documentation placeholder PublishedAllow the Azure portal URLs on your firewall or proxy server · set 89
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

learn.microsoft.comoptional TCP 80, 443 Azure documentation PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access15public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
*.aadcdn.microsoftonline-p.com TCP 80, 443 Azure portal authentication PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

aadcdn.microsoftonline-p.com TCP 80, 443 Azure portal authentication (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aadcdn.microsoftonline-p.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.aadcdn.msauthimages.net TCP 80, 443 Azure portal authentication (branding images CDN) PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

aadcdn.msauthimages.net TCP 80, 443 Azure portal authentication (branding images CDN) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aadcdn.msauthimages.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.aadcdn.msftauth.net TCP 80, 443 Azure portal authentication (sign-in CDN) PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

aadcdn.msftauth.net TCP 80, 443 Azure portal authentication (sign-in CDN) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aadcdn.msftauth.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.aadcdn.msftauthimages.net TCP 80, 443 Azure portal authentication (branding images CDN) PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

aadcdn.msftauthimages.net TCP 80, 443 Azure portal authentication (branding images CDN) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aadcdn.msftauthimages.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

graph.windows.net TCP 80, 443 Azure portal framework (Azure AD Graph) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy server · set 56Bare-domain companion of *.graph.windows.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

login.microsoftonline.com TCP 80, 443 Azure portal authentication PublishedAllow the Azure portal URLs on your firewall or proxy server · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.logincdn.msftauth.net TCP 80, 443 Azure portal authentication (login CDN) PublishedAllow the Azure portal URLs on your firewall or proxy server
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

logincdn.msftauth.net TCP 80, 443 Azure portal authentication (login CDN) (bare domain) CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.logincdn.msftauth.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.microsoftonline-p.com TCP 80, 443 Azure portal authenticationThe page adds that you may also need authentication URLs from sections 56, 59 and 97 of the Microsoft 365 URLs and IP address ranges list. PublishedAllow the Azure portal URLs on your firewall or proxy server · set 59
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.msauth.net TCP 80, 443 Azure portal authentication PublishedAllow the Azure portal URLs on your firewall or proxy server · set 59
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.msidentity.comoptional TCP 80, 443 Microsoft Entra PublishedAllow the Azure portal URLs on your firewall or proxy server · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current