182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Microsoft 365 admin portals

Reach the Microsoft 365, Exchange, SharePoint, Teams, Defender, Purview and Intune admin centers. Use with the Entra sign-in bundle.

Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Exchange · SharePoint · Teams · Purview · Defender · Intune

Admin portals sign in through Microsoft Entra, so pair this bundle with entra-admin. *.sharepoint.com, *.office.com and *.cloud.microsoft allow every tenant; use tenant-specific hosts where your filter supports them.

Cited pages since the review

7 of 7 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data

Entries with {tenant} are left out of downloads until you fill in your value.

FormatDestinationsLeft outDownload
Plain list, one per line281 Open
GSA V1 domain list245 Open
GSA V1 Graph request body245 Download
GSA V2 rules (review JSON)245 Download
GSA V2 rules (CSV)245 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/m365-admin. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle m365-admin -Value @{ tenant = '...' } from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Not determined19public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
admin.cloud.microsoft TCP/UDP 443 Microsoft 365 admin center and Exchange admin centerThe Exchange admin center opens at https://admin.cloud.microsoft/exchange. Ports follow *.cloud.microsoft (endpoint set 184); the overview page states none. PublishedMicrosoft 365 admin center overview
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

admin.microsoft.com TCP 80, 443 Microsoft 365 admin center (established address)Endpoint set 159. PublishedMicrosoft 365 URLs and IP address ranges · set 159
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.cloud.microsoft TCP/UDP 443 Unified Microsoft 365 domain for authenticated user-facing experiencesEndpoint set 184. PublishedMicrosoft 365 URLs and IP address ranges · set 184
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

intune.microsoft.com TCP 443 Microsoft Intune admin centerNot in the Microsoft 365 endpoint list. The admin center appears to use the Azure portal framework hosts listed in the Entra admin bundle; Microsoft doesn't document that. PublishedSign up or sign in to Microsoft Intune
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.office.com TCP 80, 443 Office portal and app launcherEndpoint set 147. PublishedMicrosoft 365 URLs and IP address ranges · set 147
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

prod.msocdn.com TCP 443 Microsoft 365 content deliveryEndpoint set 70; the set gives no per-host purpose. PublishedMicrosoft 365 URLs and IP address ranges · set 70
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 70 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

purview.microsoft.com TCP 443 Microsoft Purview portalEndpoint set 64. PublishedMicrosoft 365 URLs and IP address ranges · set 64
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

security.microsoft.com TCP 443 Microsoft Defender portalEndpoint set 64. PublishedMicrosoft 365 URLs and IP address ranges · set 64
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.security.microsoft.com TCP 443 Microsoft Defender portal servicesEndpoint set 64. PublishedMicrosoft 365 URLs and IP address ranges · set 64
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.sharepointonline.com TCP 80, 443 SharePoint static contentEndpoint set 37. PublishedMicrosoft 365 URLs and IP address ranges · set 37
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 SharePoint endpoint set 37 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

shellprod.msocdn.com TCP 443 Microsoft 365 content deliveryEndpoint set 70; the set gives no per-host purpose. PublishedMicrosoft 365 URLs and IP address ranges · set 70
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 70 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

spoprod-a.akamaihd.net TCP 80, 443 SharePoint content deliveryEndpoint set 37. PublishedMicrosoft 365 URLs and IP address ranges · set 37
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 SharePoint endpoint set 37 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.static.microsoft TCP/UDP 443 Static Microsoft 365 content on CDNsThe live API publishes it in set 193; the Unified Domains table on the page labels it 184. PublishedMicrosoft 365 URLs and IP address ranges · set 193
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 193 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.usercontent.microsoft TCP/UDP 443 Microsoft 365 content that needs domain isolationThe live API publishes it in set 193; the Unified Domains table on the page labels it 184. PublishedMicrosoft 365 URLs and IP address ranges · set 193
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 193 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

admin.exchange.microsoft.comoptional TCP 443 Exchange admin center (direct address)From an older page; current Exchange guidance uses admin.cloud.microsoft/exchange. Not in the Microsoft 365 endpoint list except under the optional *.microsoft.com wildcard. PublishedFeatures in the new Exchange admin center
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

compliance.microsoft.comoptional TCP 443 Legacy compliance portalEndpoint set 64 (required within the set). PublishedMicrosoft 365 URLs and IP address ranges · set 64
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

defender.microsoft.comoptional TCP 443 Microsoft Defender portal (alternate address)Endpoint set 64 (required within the set). PublishedMicrosoft 365 URLs and IP address ranges · set 64
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.portal.cloudappsecurity.comoptional TCP 443 Microsoft Defender for Cloud Apps portalEndpoint set 66 (required within the set). PublishedMicrosoft 365 URLs and IP address ranges · set 66
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 66 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

www.microsoft365.comoptional TCP 80, 443 Microsoft 365 home pageEndpoint set 147. PublishedMicrosoft 365 URLs and IP address ranges · set 147
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access10public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
13.107.6.192/32 TCP 443 Common endpoint set 64 (Allow) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

13.107.9.192/32 TCP 443 Common endpoint set 64 (Allow) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

2620:1ec:4::192/128 TCP 443 Common endpoint set 64 (Allow) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

2620:1ec:a92::192/128 TCP 443 Common endpoint set 64 (Allow) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

admin.teams.microsoft.com TCP 443 Teams admin centerStated in the page introduction, which has no anchor. Covered by *.teams.microsoft.com (endpoint set 12). PublishedManage teams in the Microsoft Teams admin center
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Teams / Skype endpoint set 12 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.protection.office.com TCP 443 Common endpoint set 64 (Allow) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

protection.office.com TCP 443 Common endpoint set 64 (Allow) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.sharepoint.com TCP 80, 443 SharePoint Online, including the tenant admin centerEndpoint set 31 (also UDP 443). Allows every tenant's SharePoint; prefer the tenant-specific host where your filter allows it. PublishedMicrosoft 365 URLs and IP address ranges · set 31
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 SharePoint endpoint set 31 (Optimize category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.teams.microsoft.com TCP 80, 443 Teams service and admin APIsEndpoint set 12; its media IP ranges and UDP ports aren't needed for administration. PublishedMicrosoft 365 URLs and IP address ranges · set 12
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Teams / Skype endpoint set 12 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

{tenant}-admin.sharepoint.comoptional TCP 443 SharePoint admin center for your tenantA narrower alternative to *.sharepoint.com. CuratedGet started with the SharePoint Online Management ShellPlaceholder form of the page's examples https://contoso-admin.sharepoint.com and https://tenant-admin.sharepoint.com.
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 SharePoint endpoint set 31 (Optimize category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current