182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Microsoft Edge

Microsoft Edge updates, configuration, profile sign-in, sync and SmartScreen on a managed device.

Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Microsoft Edge

Covers Edge 77 and later. Optional features (Copilot, Rewards, tab-group AI, Bing autosuggest, Apple and Google sign-in, feedback) are left out; the page lists them. Many features share edge.microsoft.com, so allowing that host enables them all; use Edge policies, not the allow list, to switch features off. Extension downloads use the same *.dl.delivery.mp.microsoft.com wildcard.

Cited pages since the review

2 of 2 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data
FormatDestinationsLeft outDownload
Plain list, one per line300 Open
GSA V1 domain list300 Open
GSA V1 Graph request body300 Download
GSA V2 rules (review JSON)300 Download
GSA V2 rules (CSV)300 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/edge-browser. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle edge-browser from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Not determined25public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
config.edge.skype.com TCP 443 Experimentation and Configuration serviceDelivers configurations as well as experiments. The ExperimentationAndConfigurationServiceControl policy can limit or stop it (RestrictedMode); keep it allowed unless you set that policy. PublishedAllow list for Microsoft Edge endpoints · set 189
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.dl.delivery.mp.microsoft.com TCP 80, 443 Edge and extension downloads and updatesThe page's tip: one wildcard instead of the individual download hosts. The update service picks the host; some use plain HTTP. PublishedAllow list for Microsoft Edge endpoints · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

edge.microsoft.com TCP 80, 443 Browser support services: component updates and revocation metadata, sync, cloud site list, management service, web content filtering, password monitorPublished on HTTP and HTTPS. The page lists it under several features; this one host carries them all. PublishedAllow list for Microsoft Edge endpoints · set 181
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

graph.microsoft.com TCP 443 Profile sign-in and Purview DLP integrationAlso listed under Microsoft Graph API for Data Loss Prevention in Edge for Business. PublishedAllow list for Microsoft Edge endpoints · set 56
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

login.live.com TCP 443 Profile sign-inMicrosoft lists it for both personal and Entra ID profiles. PublishedAllow list for Microsoft Edge endpoints · set 97
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

login.microsoft.com TCP 443 Profile sign-in PublishedAllow list for Microsoft Edge endpoints · set 56
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.api.cdp.microsoft.com TCP 443 Update service: checks for new Edge versionsPublished as https://msedge.api.cdp.microsoft.com. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.smartscreen-prod.microsoft.com TCP 443 Microsoft Defender SmartScreen PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.smartscreen.microsoft.com TCP 443 Microsoft Defender SmartScreenBlocking it disables protection from malicious sites and downloads. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

substrate.office.com TCP 443 Profile sign-in PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.urs.microsoft.com TCP 443 Microsoft Defender SmartScreen PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

api.aadrm.comoptional TCP 443 Azure Information Protection for synced dataNeeded when sync is on; most tenants. Germany and China tenants use api.aadrm.de and api.aadrm.cn. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 73 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

clients.config.office.netoptional TCP 443 Microsoft Edge management service configuration profilesNeeded only if you manage Edge through the Microsoft 365 admin center's Edge management service. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 47 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.cloudmessaging.edge.microsoft.comoptional TCP 443 Sync notifications (cloud messaging)Published as https:// and wss:// (WebSocket). Needed when sync is on. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.do.dsp.mp.microsoft.comoptional TCP 80, 443 Delivery Optimization for Edge downloads (client to service)Optional. Peer-to-peer Delivery Optimization also needs inbound TCP 7680 between clients. PublishedAllow list for Microsoft Edge endpoints · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

edgepasskeysenclave.microsoft.comoptional TCP 443 Passkey cloud authenticatorPublished as wss:// (WebSocket); port 443 assumed. Edge uses it as its cloud passkey authenticator. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.b.dl.delivery.mp.microsoft.comoptional TCP 80 Edge download location (HTTP)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.b.tlu.dl.delivery.mp.microsoft.comoptional TCP 80 Edge download location (HTTP)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.f.dl.delivery.mp.microsoft.comoptional TCP 80 Edge download location (HTTP)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.f.tlu.dl.delivery.mp.microsoft.comoptional TCP 80 Edge download location (HTTP)Narrower alternative to *.dl.delivery.mp.microsoft.com; list all eight download hosts if you use them instead. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.sb.dl.delivery.mp.microsoft.comoptional TCP 443 Edge download location (HTTPS)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.sb.tlu.dl.delivery.mp.microsoft.comoptional TCP 443 Edge download location (HTTPS)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.sf.dl.delivery.mp.microsoft.comoptional TCP 443 Edge download location (HTTPS)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

msedge.sf.tlu.dl.delivery.mp.microsoft.comoptional TCP 443 Edge download location (HTTPS)Narrower alternative to the wildcard. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

privacy.microsoft.comoptional TCP 443 Privacy statement during sign-inListed with the sign-in hosts; marked optional here because it serves the privacy statement. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access5public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
cdn.odc.officeapps.live.com TCP 443 Profile sign-inMicrosoft doesn't say what it does. PublishedAllow list for Microsoft Edge endpoints · set 91
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 46 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

login.microsoftonline.com TCP 443 Profile sign-inThe page says its sign-in list isn't exhaustive. PublishedAllow list for Microsoft Edge endpoints · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

login.windows.net TCP 443 Profile sign-in PublishedAllow list for Microsoft Edge endpoints · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

logincdn.msauth.net TCP 443 Profile sign-in (sign-in CDN) PublishedAllow list for Microsoft Edge endpoints
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

odc.officeapps.live.com TCP 443 Profile sign-inMicrosoft doesn't say what it does. PublishedAllow list for Microsoft Edge endpoints
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 46 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current