Microsoft Entra sign-in and admin
Sign in to Microsoft Entra ID, use the Entra admin center and Microsoft Graph, and register security info for MFA.
Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Microsoft Entra · Microsoft Graph
Sets 56 and 59 are the Microsoft 365 identity sets; 84 and 125 cover certificate revocation. The Entra FAQ publishes *.entra.microsoft.com and points to the Azure portal safelist, so the portal framework hosts are included; Microsoft does not document which of them the Entra admin center actually calls.
Cited pages since the review
5 of 5 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint data| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 107 | 0 | Open |
| GSA V1 domain list | 91 | 16 | Open |
| GSA V1 Graph request body | 91 | 16 | Download |
| GSA V2 rules (review JSON) | 91 | 16 | Download |
| GSA V2 rules (CSV) | 91 | 16 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/entra-admin. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle entra-admin from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Expected to reach web filtering20expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
*. |
TCP 80, 443 | Azure portal extension services | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
ext. |
TCP 80, 443 | Azure portal extension services (bare domain) | CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.ext.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'Internet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 80, 443 | Azure AD Graph subdomains used by the portal framework | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 80, 443 | Azure portal extension hosting | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
hosting-ms. |
TCP 80, 443 | Azure portal extension hosting (bare domain) | CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.hosting-ms.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'Internet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
hosting. |
TCP 80, 443 | Azure portal partner extension hosting | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
hosting. |
TCP 80, 443 | Azure portal extension hosting (bare domain) | CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.hosting.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'Internet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
management. |
TCP 80, 443 | Azure Resource Manager, part of the portal framework | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 80, 443 | Azure portal framework shared by the Entra admin centerIncluded because the Entra FAQ points to the Azure portal safelist; Microsoft doesn't document which framework hosts the Entra admin center uses. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 80, 443 | Azure portal React blades | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
reactblade. |
TCP 80, 443 | Azure portal React blades (bare domain) | CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.reactblade.portal.azure.net. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'Internet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*.optional |
TCP 80, 443 | Microsoft Entra portal servicesLabelled Microsoft Entra on the page. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
aad.optional |
TCP 80, 443 | Microsoft Entra portal services (bare domain) | CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aad.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'Internet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*.optional |
TCP 80, 443 | Microsoft Entra Connect Health portalLabelled Microsoft Entra on the page. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
aadconnecthealth.optional |
TCP 80, 443 | Microsoft Entra Connect Health portal (bare domain) | CuratedAllow the Azure portal URLs on your firewall or proxy serverBare-domain companion of *.aadconnecthealth.azure.com. The page lists only the wildcard, but its Important note says: 'For endpoints with wildcards, we also advise you to add the URL without the wildcard.'Internet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
ad.optional |
TCP 80, 443 | Microsoft Entra portal servicesLabelled Microsoft Entra on the page. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
api.optional |
TCP 80, 443 | Privileged Identity Management APILabelled Microsoft Entra on the page. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
identitygovernance.optional |
TCP 80, 443 | Microsoft Entra ID GovernanceThe same section also lists iga.azure.com and elm.iga.azure.com. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
mspim.optional |
TCP 80, 443 | Privileged Identity ManagementLabelled Microsoft Entra on the page; relevant when admins activate roles with PIM. | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
portal.optional |
TCP 80, 443 | Azure portal address used by Entra admin center links | PublishedAllow the Azure portal URLs on your firewall or proxy serverInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
Not determined39public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
*. |
TCP 80, 443 | Microsoft Entra authentication services, including multifactor authenticationEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cacerts. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cert. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Certificate revocation listsEndpoint set 84. Revocation checks use plain HTTP on port 80. | PublishedMicrosoft 365 URLs and IP address ranges · set 84Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl3. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl4. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Microsoft Entra admin centerThe FAQ also says to include the Azure portal safelist URLs. No port stated; HTTPS assumed. | PublishedFrequently asked questions about Microsoft EntraMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
entra. |
TCP 443 | Microsoft Entra admin center address | CuratedFrequently asked questions about Microsoft EntraThe FAQ publishes only *.entra.microsoft.com, which doesn't match the admin center's own address; the Azure portal safelist advises adding the bare domain next to each wildcard.Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
graph. |
TCP 80, 443 | Microsoft Graph, used by the admin centers and admin toolsEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Microsoft Graph subdomains used by the portal frameworkDoesn't match graph.microsoft.com itself, which is listed separately. | PublishedAllow the Azure portal URLs on your firewall or proxy serverMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Azure portal extension hosting | PublishedAllow the Azure portal URLs on your firewall or proxy serverNot determined · possible, not confirmedBroader than the Microsoft 365 entries it includes (such as set 73): those parts are expected to go to a Microsoft profile and the rest to Internet Access. |
isrg. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
login. |
TCP 80, 443 | Microsoft Entra sign-in endpointEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
mscrl. |
TCP 80, 443 | Microsoft certificate revocation list distributionEndpoint set 125. | PublishedMicrosoft 365 URLs and IP address ranges · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
myaccount. |
TCP 443 | My Account portalNot in the Microsoft 365 endpoint list except under the optional *.microsoft.com wildcard. | PublishedCombined registration for SSPR and Microsoft Entra multifactor authenticationMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
mysignins. |
TCP 443 | My Sign-ins and Security info, including MFA registrationAppears in the page's https://mysignins.microsoft.com/security-info links. Not in the Microsoft 365 endpoint list except under the optional *.microsoft.com wildcard. | PublishedCombined registration for SSPR and Microsoft Entra multifactor authenticationMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | OCSP for Microsoft certificatesEndpoint set 125. | PublishedMicrosoft 365 URLs and IP address ranges · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp2. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocspx. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
oneocsp. |
TCP 80, 443 | OCSP for Microsoft certificatesEndpoint set 125, which also lists the third-party CA revocation hosts merged from the live list. | PublishedMicrosoft 365 URLs and IP address ranges · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
secure. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
aka.optional |
TCP 443 | Microsoft short links such as aka.ms/mysecurityinfoEndpoint set 17. | PublishedMicrosoft 365 URLs and IP address ranges · set 17Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
appmanagement.optional |
TCP 80, 443 | Microsoft Entra application managementLabelled Microsoft Entra on the page. | PublishedAllow the Azure portal URLs on your firewall or proxy serverMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
login.optional |
TCP 80, 443 | Microsoft account sign-inOnly for Microsoft account or guest scenarios; also optional endpoint sets 97 and 116. | PublishedAllow the Azure portal URLs on your firewall or proxy server · set 97Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
Probably taken before Internet Access48public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
20. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
20. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
20. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1006:2000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1007:200::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1016:1400::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1017::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1026:3000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1027:1::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1036:3000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1037:1::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1046:2000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1047:1::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1056:2000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1057:2::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
40. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
accounts. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
adminwebservice. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
becws. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
ccs. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
clientconfig. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
companymanager. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
device. |
TCP 80, 443 | Device-based authentication for device Conditional AccessAlso endpoint set 56. The page says to exclude it from TLS break-and-inspect. | PublishedConfigure Microsoft Entra hybrid join · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
enterpriseregistration. |
TCP 80, 443 | Device registration for Microsoft Entra join, hybrid join and device Conditional AccessAlso endpoint set 59. Exclude from TLS inspection per the same page. | PublishedConfigure Microsoft Entra hybrid join · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
graph. |
TCP 80, 443 | Legacy Azure AD GraphEndpoint set 56. Azure AD Graph is retiring but is still published as required. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login-us. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 80, 443 | Microsoft Entra sign-in and token endpointEndpoint set 56. Also listed by the Azure portal safelist and the Microsoft Entra hybrid join network requirements. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 80, 443 | Legacy Microsoft Entra sign-in endpointEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
logincert. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
loginex. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Legacy identity and sign-in content deliveryEndpoint set 59; also on the Azure portal safelist. | PublishedMicrosoft 365 URLs and IP address ranges · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Microsoft Entra identity service hostsEndpoint set 59; set 56 lists the specific hosts. | PublishedMicrosoft 365 URLs and IP address ranges · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Sign-in page content deliveryEndpoint set 59. | PublishedMicrosoft 365 URLs and IP address ranges · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Sign-in company branding imagesEndpoint set 59. | PublishedMicrosoft 365 URLs and IP address ranges · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Sign-in page content deliveryEndpoint set 59. Covers the narrower *.aadcdn.msftauth.net and *.logincdn.msftauth.net listed by the Azure portal safelist. | PublishedMicrosoft 365 URLs and IP address ranges · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Sign-in company branding imagesEndpoint set 59. | PublishedMicrosoft 365 URLs and IP address ranges · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Microsoft Entra identity serviceEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Microsoft Entra identity serviceEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
nexus. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
provisioningapi. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
account.optional |
TCP 80, 443 | Legacy multifactor authentication and access panel endpointEndpoint set 56 (required within the set). | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
api.optional |
TCP 80, 443 | Self-service password reset APIEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
autologon.optional |
TCP 80, 443 | Seamless single sign-onOnly if you use seamless SSO. Also endpoint set 56. | PublishedConfigure Microsoft Entra hybrid join · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
passwordreset.optional |
TCP 80, 443 | Self-service password resetEndpoint set 56. | PublishedMicrosoft 365 URLs and IP address ranges · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |