Certificate revocation and issuers
Revocation (CRL and OCSP) and issuer (AIA) hosts for the certificate authorities behind Microsoft's services. Blocked revocation checks make TLS clients either refuse the connection or wait for timeouts before giving up, so sign-ins, updates and agents fail or slow down.
Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Azure · Microsoft 365 connectivity
Applies to any machine that talks to Microsoft services, including admin workstations. Revocation and chain-building requests are plain HTTP on port 80 by design, so a TLS-only allow list breaks them. The Azure CA page is the authoritative list for Azure and says to watch its change log; on October 8, 2024 it dropped crl.microsoft.com, mscrl.microsoft.com and ocsp.msocsp.com, which Microsoft 365 sets 84 and 125 still publish as required. Sets 84 and 125 are merged for the third-party CAs Microsoft 365 also uses. The .cn hosts are for Microsoft Azure operated by 21Vianet.
Cited pages since the review
3 of 3 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint data| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 35 | 0 | Open |
| GSA V1 domain list | 33 | 2 | Open |
| GSA V1 Graph request body | 35 | 0 | Download |
| GSA V2 rules (review JSON) | 35 | 0 | Download |
| GSA V2 rules (CSV) | 35 | 0 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/certificate-revocation. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle certificate-revocation from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Not determined35public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
cacerts. |
TCP 80 | Issuer certificates (AIA) for DigiCert certificate authoritiesAlso Microsoft 365 endpoint set 125. | PublishedAzure Certificate Authority details · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cacerts. |
TCP 80 | Issuer certificates (AIA) for GeoTrust certificate authoritiesMicrosoft 365 set 125 publishes the broader *.geotrust.com. | PublishedAzure Certificate Authority detailsMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
caissuers. |
TCP 80 | Issuer certificates (AIA) for Microsoft certificate authoritiesNeeded when a server doesn't send its full chain and the client must fetch an intermediate. | PublishedAzure Certificate Authority detailsMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cert. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Certificate revocation lists for Microsoft certificate authoritiesEndpoint set 84 (Default, required). The Azure CA page removed it on October 8, 2024; Defender for Endpoint still lists it. | PublishedMicrosoft 365 URLs and IP address ranges · set 84Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl3. |
TCP 80 | Certificate revocation lists for DigiCert certificate authoritiesAlso Microsoft 365 endpoint set 125. | PublishedAzure Certificate Authority details · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl4. |
TCP 80 | Certificate revocation lists for DigiCert certificate authoritiesAlso Microsoft 365 endpoint set 125. | PublishedAzure Certificate Authority details · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ctldl. |
TCP 80 | Windows automatic root update and certificate trust lists, including the disallowed listWindows only. Disconnected devices must get trust list updates another way. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
isrg. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
mscrl. |
TCP 80, 443 | Certificate revocation lists for Microsoft certificate authoritiesEndpoint set 125 (Default, required). The Azure CA page removed it on October 8, 2024. | PublishedMicrosoft 365 URLs and IP address ranges · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80 | OCSP for DigiCert certificate authoritiesAlso Microsoft 365 endpoint set 125. | PublishedAzure Certificate Authority details · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | OCSP for Microsoft certificate authoritiesEndpoint set 125 (Default, required). The Azure CA page removed it on October 8, 2024. | PublishedMicrosoft 365 URLs and IP address ranges · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp2. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocspx. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
oneocsp. |
TCP 80 | OCSP for Microsoft certificate authoritiesAlso Microsoft 365 endpoint set 125. | PublishedAzure Certificate Authority details · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
secure. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80 | Issuer certificates (AIA) and revocation lists for Microsoft certificate authoritiesListed under both AIA and CRL. The page's download links sit under /pkiops/; a path-aware proxy can narrow the host to the URL entries below. | PublishedAzure Certificate Authority details · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cacerts.optional |
TCP 80 | Issuer certificates (AIA) for DigiCert certificate authorities (China)Needed for Microsoft Azure operated by 21Vianet. | PublishedAzure Certificate Authority detailsNot determined · possible, not confirmedLooks like a certificate validation host and isn't in the Microsoft 365 list. Microsoft documents that the Entra system profile covers certificate validation but lists no hosts, so this can go either way. |
crl.optional |
TCP 80 | Certificate revocation lists for DigiCert certificate authorities (China)Needed for Microsoft Azure operated by 21Vianet. | PublishedAzure Certificate Authority detailsNot determined · possible, not confirmedLooks like a certificate validation host and isn't in the Microsoft 365 list. Microsoft documents that the Entra system profile covers certificate validation but lists no hosts, so this can go either way. |
ocsp.optional |
TCP 80 | OCSP for DigiCert certificate authorities (China)Needed for Microsoft Azure operated by 21Vianet. | PublishedAzure Certificate Authority detailsNot determined · possible, not confirmedLooks like a certificate validation host and isn't in the Microsoft 365 list. Microsoft documents that the Entra system profile covers certificate validation but lists no hosts, so this can go either way. |
www.optional |
TCP 80 | Older Microsoft PKI revocation lists (path-scoped alternative to www.microsoft.com)Published without a scheme; port 80. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www.optional |
TCP 80 | Microsoft PKI certificates and revocation lists (path-scoped alternative to www.microsoft.com)Published without a scheme; port 80. Use it instead of www.microsoft.com only when your filter matches URL paths. | PublishedMicrosoft Defender for Endpoint streamlined connectivity URLs - commercialMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |