Intune-managed Windows devices
The Intune admin center plus what managed Windows devices need: enrollment and check-in, Win32 app and script delivery, push notifications, Autopilot, attestation, the Store API and optional Remote Help.
Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Intune · Windows
Intune says the endpoint web service lists alone are insufficient and to use its consolidated list, so the entries follow the Intune page. The MEM sets add the service IP ranges; stale sets 170, 179 and 182 (azureedge.net hosts) are not referenced. Do not TLS-inspect *.manage.microsoft.com, *.dm.microsoft.com, the attestation hosts or the Store API, and allow HTTP partial responses for script and Win32 app content. Some tasks need unauthenticated proxy access to manage.microsoft.com, *.azureedge.net and graph.microsoft.com.
Cited pages since the review
5 of 5 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint data| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 227 | 0 | Open |
| GSA V1 domain list | 146 | 81 | Open |
| GSA V1 Graph request body | 146 | 81 | Download |
| GSA V2 rules (review JSON) | 146 | 81 | Download |
| GSA V2 rules (CSV) | 146 | 81 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/intune-admin. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle intune-admin from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Expected to reach web filtering40expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
certauth. |
TCP 80, 443 | Entra device registration (certificate auth)Page-only; not in live API set 59. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 443 | TPM attestation (Autopilot self-deploying mode and pre-provisioning)Not in the Intune page or MEM API. Page says HTTPS URLs. | PublishedWindows Autopilot requirementsInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 80 | Network Connection Status Indicator (Autopilot requires internet detection)HTTP-only: page says it must be resolvable via DNS and accessible via HTTP. | PublishedWindows Autopilot requirementsInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0101lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0102lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0201lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0202lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0401lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0402lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0501lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0502lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0601lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0602lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0701lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0702lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0801lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0901lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsua0902lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0101lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0102lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0201lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0202lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0301lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0302lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0501lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0502lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0601lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0701lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0801lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsub0901lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsuc0101lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsuc0201lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsuc0301lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsuc0501lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsuc0601lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsud0101lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
amsuin01lmsas.optional |
TCP 443 | Autopilot / collect-diagnostics upload storage (region-specific)Set 182 (Intune page only; not in live API). Page marks Required; false here: non-blocking, tenant-region host only. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
cdn.optional |
— | Listed in Intune consolidated FQDN list (purpose not stated)Appears only in the consolidated list; no section, set ID, port or purpose is given. Not in the MEM API. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
intunemaape6.optional |
TCP 443 | Microsoft Azure Attestation (North America)Listed in the MAA section and GSA script but NOT in live API set 186 nor the Intune consolidated list. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*.optional |
— | Listed in Intune consolidated FQDN list (purpose not stated)Appears only in the consolidated list; no section, set ID, port or purpose is given. Not in the MEM API. | PublishedNetwork endpoints for Microsoft IntuneInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
Not determined98public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
account. |
TCP 443 | Microsoft account / device authenticationSet 97 (M365 Common service area; API marks it optional for Outlook mobile, Intune page marks Required). | PublishedNetwork endpoints for Microsoft Intune · set 97Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
adl. |
TCP 80, 443 | Windows compatibility database updatesSet 164. | PublishedNetwork endpoints for Microsoft Intune · set 19Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 19 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cdn. |
TCP 80, 443 | Microsoft-hosted Win32 Store app fallback cacheWin32 Store app installers otherwise download from publisher-specific URLs (winget show [PackageId]). | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
clientconfig. |
TCP 443 | Autopilot WNS dependencySet 169. | PublishedNetwork endpoints for Microsoft Intune · set 169Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 169 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
config. |
TCP 443 | Feature deployment / flighting dependencySet 189. Page marks Required; live API marks set 189 required=false with note: feature flighting may not function if not included. | PublishedNetwork endpoints for Microsoft Intune · set 189Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Windows Update / Store delivery (Autopilot dependency)Set 164 on page; not in live API set 164. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
displaycatalog. |
TCP 80, 443 | Microsoft Store API (AppInstallManager) catalogNeeded when deploying Microsoft Store apps. Intune: SSL inspection not supported for Store API endpoints. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Delivery Optimization metadata / Windows and Store contentSets 172/164. Content is largely plain HTTP (port 80); proxy must allow byte-range requests. | PublishedNetwork endpoints for Microsoft Intune · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
dl. |
TCP 80, 443 | Windows Update / Delivery Optimization content (apex host)In live API set 164 and the consolidated list, not in the per-section tables. | PublishedNetwork endpoints for Microsoft Intune · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Intune / Defender for Endpoint security settings management / Endpoint Privilege Management enrollment, check-in and reportingListed in set 163 on the Intune page but NOT in live API set 163. Also listed in #microsoft-defender-for-endpoint and #microsoft-intune-endpoint-privilege-management. Intune states SSL/TLS inspection is not supported for this endpoint. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Delivery Optimization cloud serviceSet 172 (page-only; not in live API) and API set 164. Must bypass TLS inspection (certificate pinning on geo.prod.do.dsp.mp.microsoft.com and array*.prod.do.dsp.mp.microsoft.com) and must not have client IP altered: https://learn.microsoft.com/en-us/windows/deployment/do/delivery-optimization-proxy#endpoints-to-exempt-from-tls-inspection | PublishedNetwork endpoints for Microsoft Intune · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ecs. |
TCP 443 | Feature deployment dependencySet 189 on the Intune page only; not in live API set 189. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ekcert. |
TCP 443 | Qualcomm firmware TPM EK certificate retrievalSet 173. | PublishedNetwork endpoints for Microsoft Intune · set 173Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ekop. |
TCP 443 | Intel firmware TPM EK certificate retrieval (Autopilot self-deploying / pre-provisioning)Set 173. Autopilot requirements: https://ekop.intel.com/ekcertservice. | PublishedNetwork endpoints for Microsoft Intune · set 173Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 173 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
emdl. |
TCP 80 | Windows Update download endpointHTTP-only (Windows Update troubleshooting says HTTP; do not force HTTPS). Also in GSA script. Not on the Intune page. | PublishedWindows Update issues troubleshootingMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
EnterpriseEnrollment. |
TCP 80, 443 | Windows MDM enrollment discoveryPage-only (not in live API set 163); covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
fd. |
TCP 443 | Organizational messagesSet 192 (required per page and API); only exercised if organizational messages are used. | PublishedNetwork endpoints for Microsoft Intune · set 192Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ftpm. |
TCP 443 | AMD firmware TPM EK certificate retrievalSet 173. | PublishedNetwork endpoints for Microsoft Intune · set 173Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 173 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
go-amer. |
TCP 443 | Listed with IME CDN and Remote Help endpoints (NA / rest of world tenants)Region-specific. Page lists it in the IME regional table and in Remote Help set 181 but does not state its purpose. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
go-apac. |
TCP 443 | Listed with IME CDN and Remote Help endpoints (APAC tenants)Region-specific. Page lists it in the IME regional table and in Remote Help set 181 but does not state its purpose. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
go-eu. |
TCP 443 | Listed with IME CDN and Remote Help endpoints (EU tenants)Region-specific. Page lists it in the IME regional table and in Remote Help set 181 but does not state its purpose. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
go. |
TCP 80, 443 | Endpoint discoveryIntune page set 190; set 190 does not exist in the live MEM API (go.microsoft.com is in Common set 89). | PublishedNetwork endpoints for Microsoft Intune · set 89Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
graph. |
TCP 80, 443 | Microsoft Graph (Intune requires unauthenticated proxy access for some tasks; admin center data plane)Ports taken from M365 Common set 56, which contains graph.microsoft.com; the Intune page states only the unauthenticated-proxy requirement. | PublishedNetwork endpoints for Microsoft Intune · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswda-afd-hotfix. |
TCP 443 | Intune Management Extension CDN (North America tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in North America. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswda-afd-primary. |
TCP 443 | Intune Management Extension CDN (North America tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in North America. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswda-afd-secondary. |
TCP 443 | Intune Management Extension CDN (North America tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in North America. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswdb-afd-hotfix. |
TCP 443 | Intune Management Extension CDN (Europe tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in Europe. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswdb-afd-primary. |
TCP 443 | Intune Management Extension CDN (Europe tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in Europe. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswdb-afd-secondary. |
TCP 443 | Intune Management Extension CDN (Europe tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in Europe. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswdc-afd-hotfix. |
TCP 443 | Intune Management Extension CDN (Asia Pacific tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in Asia Pacific. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswdc-afd-primary. |
TCP 443 | Intune Management Extension CDN (Asia Pacific tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in Asia Pacific. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
imeswdc-afd-secondary. |
TCP 443 | Intune Management Extension CDN (Asia Pacific tenants): Win32 apps, PowerShell scripts, remediations, custom complianceOnly needed for tenants in Asia Pacific. Proxy must allow HTTP partial responses (byte ranges). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intune. |
TCP 443 | Microsoft Intune admin centerThe admin center also needs the Entra sign-in endpoints and graph.microsoft.com. It appears to use the Azure portal framework hosts in the entra-admin bundle; Microsoft does not document that. | PublishedSign up or sign in to Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
licensing. |
TCP 80, 443 | Microsoft Store API licensingIntune: SSL inspection not supported. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
login. |
TCP 443 | Microsoft account / device authentication; Windows Autopilot deployment serviceSet 97. Autopilot requirements also list https://login.live.com for the Autopilot Deployment Service. | PublishedNetwork endpoints for Microsoft Intune · set 97Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Intune client and host service: enrollment, check-in, policy, IME/Win32 content (AFD)M365 endpoint set 163 (Allow, required). Intune states SSL/TLS inspection is not supported for this endpoint. Covers all *.manage.microsoft.com hosts listed below. | PublishedNetwork endpoints for Microsoft Intune · set 163Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
manage. |
TCP 80, 443 | Intune client and host service (apex)M365 endpoint set 163. Page also says some tasks require unauthenticated proxy access to manage.microsoft.com. | PublishedNetwork endpoints for Microsoft Intune · set 163Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Windows Push Notification Services (device actions, immediate sync)Set 171. WNS docs: direct connection recommended; WNS may not support proxies. Page also lists sin.notify.windows.com (covered). | PublishedNetwork endpoints for Microsoft Intune · set 171Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 171 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Delivery Optimization service (Autopilot dependency)Set 164 on page (API uses *.do.dsp.mp.microsoft.com instead). Covered by *.do.dsp.mp.microsoft.com. No TLS inspection. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
purchase. |
TCP 80, 443 | Microsoft Store API purchase/acquisitionIntune: SSL inspection not supported. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ris. |
TCP 443 | Organizational messagesSet 192. | PublishedNetwork endpoints for Microsoft Intune · set 192Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Autopilot WNS dependencySet 169. Page also lists c.s-microsoft.com (covered). | PublishedNetwork endpoints for Microsoft Intune · set 169Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 169 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
storeedgefd. |
TCP 80, 443 | Microsoft Store API front doorIntune: SSL inspection not supported. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swda01-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swda02-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdb01-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdb02-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdc01-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdc02-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Intune page set 170 contains a typo for this host ("swdc02-mscdn.manage.microsoft<.com"), so the GSA script is cited for the exact string. Covered by *.manage.microsoft.com. | PublishedAdd Intune device compliance bypasses to Global Secure Access Internet AccessMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdd01-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdd02-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdin01-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
swdin02-mscdn. |
TCP 80, 443 | Win32 app content CDN (MEM - Win32Apps)Set 170 (API still lists legacy *-mscdn.azureedge.net). Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
time. |
UDP 123 | NTP time sync (Autopilot)Set 165. UDP only. | PublishedNetwork endpoints for Microsoft Intune · set 165Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 165 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
tsfe. |
TCP 80, 443 | Windows Update traffic shaping / content regulationSet 164. | PublishedNetwork endpoints for Microsoft Intune · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Windows Update service (Autopilot dependency)Set 164. | PublishedNetwork endpoints for Microsoft Intune · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
windowsphone. |
TCP 443 | Autopilot WNS dependencySet 169. | PublishedNetwork endpoints for Microsoft Intune · set 169Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 169 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Windows Update (Autopilot dependency)Set 164. Windows docs list this as HTTP; port 80 must be allowed. | PublishedNetwork endpoints for Microsoft Intune · set 164Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Windows Push Notification Services client channelSet 171. Page also lists sinwns1011421.wns.windows.com (covered). See https://learn.microsoft.com/en-us/windows/apps/develop/notifications/push-notifications/firewall-allowlist-config#fqdns-vips-ips-and-ports. | PublishedNetwork endpoints for Microsoft Intune · set 35Microsoft traffic profile · possible, not confirmedIn Microsoft 365 SharePoint endpoint set 35 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ztd. |
TCP 443 | Windows Autopilot Deployment ServiceListed as https://ztd.dds.microsoft.com. Not in the Intune page or MEM API. | PublishedWindows Autopilot requirementsMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
aam-content-cdn.optional |
TCP 80, 443 | Enterprise App Catalog app contentSet 170; page says only for Enterprise App Catalog apps. Covered by *.manage.microsoft.com. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
aka.optional |
— | Listed in Intune consolidated FQDN list (purpose not stated)Appears only in the consolidated list; no section, set ID, port or purpose is given. Not in the MEM API. | PublishedNetwork endpoints for Microsoft Intune · set 17Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
api.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 69Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
— | Legacy Azure CDN (Intune says some tasks require unauthenticated proxy access)Very broad shared CDN wildcard. Intune Win32/IME/AOSP content has moved to *.manage.microsoft.com hosts on the current page; only add if a specific failure needs it. No ports stated. | PublishedNetwork endpoints for Microsoft IntuneNot determined · possible, not confirmedBroader than the Microsoft 365 entries it includes (such as set 27): those parts are expected to go to a Microsoft profile and the rest to Internet Access. |
config.optional |
TCP 443 | Office Customization Service (M365 Apps policy)Set 150; category Default, not marked Required. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ecs.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
edge.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
edge.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 80, 443 | Windows Update / Delivery Optimization download (GSA bypass list)Only in the GSA bypass script (rule ports 80/443). emdl.ws.microsoft.com itself is HTTP-only per Windows Update troubleshooting. | PublishedAdd Intune device compliance bypasses to Global Secure Access Internet AccessMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | IME client health diagnostics; Endpoint analytics; EPM reportingOptional (Endpoint analytics). Endpoint analytics prerequisites list https://*.events.data.microsoft.com (https://learn.microsoft.com/en-us/intune/endpoint-analytics/#prerequisites). Also in Remote Help set 181 and EPM section. | PublishedNetwork endpoints for Microsoft Intune · set 69Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape1.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape10.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape11.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape12.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape13.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape17.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape18.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape19.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape2.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape3.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape4.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape5.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape7.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape8.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intunemaape9.optional |
TCP 443 | Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)Set 186. Needed for Device Health compliance settings; tenant-region host only. No SSL inspection. | PublishedNetwork endpoints for Microsoft Intune · set 186Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
lgmsapeweu.optional |
TCP 443 | Autopilot automatic diagnostics upload (legacy host)Still in Autopilot requirements and live API set 182, but the Intune page set 182 now lists region-specific amsu*lmsas hosts instead. | PublishedWindows Autopilot requirements · set 182Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 182 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 181 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Office Customization ServiceSet 150; not marked Required. | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 78 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
remoteassistanceprodacs.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 181 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
remoteassistanceprodacseu.optional |
TCP 443 | Remote Help (optional feature)Set 181; EU customers only. | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 181 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
remotehelp.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)In live API set 181 and the GSA script, but no longer on the Intune Remote Help table. | PublishedAdd Intune device compliance bypasses to Global Secure Access Internet Access · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
wcpstatic.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help web pubsubSet 187. Live API note: Android Remote Help requires this endpoint. Page also lists AMSUA0101-RemoteAssistService-pubsub.webpubsub.azure.com (covered). | PublishedNetwork endpoints for Microsoft Intune · set 187Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 187 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
Probably taken before Internet Access89public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
104. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
104. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
172. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
172. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
172. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
172. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
172. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
172. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
20. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
4. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
40. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
48. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
52. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
52. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
52. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
52. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
52. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
52. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
57. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
57. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
57. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
57. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
57. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
68. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
74. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
74. |
TCP 80, 443 | MEM endpoint set 163 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 163 · set 163Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Intune (MEM) endpoint set 163 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
enterpriseregistration. |
TCP 80, 443 | Entra device registrationSet 59 (Common). | PublishedNetwork endpoints for Microsoft Intune · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
graph. |
TCP 80, 443 | Azure AD Graph (Entra) dependencySet 56 (Common). | PublishedNetwork endpoints for Microsoft Intune · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 80, 443 | Microsoft Entra authenticationSet 56 (Common). Full set 56 in API has more identity FQDNs. | PublishedNetwork endpoints for Microsoft Intune · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
aadcdn.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft IntuneMicrosoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
aadcdn.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft IntuneMicrosoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
alcdn.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft IntuneMicrosoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
teams.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 12Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Teams / Skype endpoint set 12 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Remote Help (optional feature)Set 181 (page marks Required for Remote Help). | PublishedNetwork endpoints for Microsoft Intune · set 181Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Teams / Skype endpoint set 12 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |