Microsoft 365 admin portals
Reach the Microsoft 365, Exchange, SharePoint, Teams, Defender, Purview and Intune admin centers. Use with the Entra sign-in bundle.
Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Exchange · SharePoint · Teams · Purview · Defender · Intune
Admin portals sign in through Microsoft Entra, so pair this bundle with entra-admin. *.sharepoint.com, *.office.com and *.cloud.microsoft allow every tenant; use tenant-specific hosts where your filter supports them.
Cited pages since the review
7 of 7 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint dataEntries with {tenant} are left out of downloads until you fill in your value.
| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 28 | 1 | Open |
| GSA V1 domain list | 24 | 5 | Open |
| GSA V1 Graph request body | 24 | 5 | Download |
| GSA V2 rules (review JSON) | 24 | 5 | Download |
| GSA V2 rules (CSV) | 24 | 5 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/m365-admin. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle m365-admin -Value @{ tenant = '...' } from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Not determined19public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
admin. |
TCP/UDP 443 | Microsoft 365 admin center and Exchange admin centerThe Exchange admin center opens at https://admin.cloud.microsoft/exchange. Ports follow *.cloud.microsoft (endpoint set 184); the overview page states none. | PublishedMicrosoft 365 admin center overviewMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
admin. |
TCP 80, 443 | Microsoft 365 admin center (established address)Endpoint set 159. | PublishedMicrosoft 365 URLs and IP address ranges · set 159Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP/UDP 443 | Unified Microsoft 365 domain for authenticated user-facing experiencesEndpoint set 184. | PublishedMicrosoft 365 URLs and IP address ranges · set 184Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
intune. |
TCP 443 | Microsoft Intune admin centerNot in the Microsoft 365 endpoint list. The admin center appears to use the Azure portal framework hosts listed in the Entra admin bundle; Microsoft doesn't document that. | PublishedSign up or sign in to Microsoft IntuneMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Office portal and app launcherEndpoint set 147. | PublishedMicrosoft 365 URLs and IP address ranges · set 147Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
prod. |
TCP 443 | Microsoft 365 content deliveryEndpoint set 70; the set gives no per-host purpose. | PublishedMicrosoft 365 URLs and IP address ranges · set 70Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 70 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
purview. |
TCP 443 | Microsoft Purview portalEndpoint set 64. | PublishedMicrosoft 365 URLs and IP address ranges · set 64Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
security. |
TCP 443 | Microsoft Defender portalEndpoint set 64. | PublishedMicrosoft 365 URLs and IP address ranges · set 64Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Microsoft Defender portal servicesEndpoint set 64. | PublishedMicrosoft 365 URLs and IP address ranges · set 64Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | SharePoint static contentEndpoint set 37. | PublishedMicrosoft 365 URLs and IP address ranges · set 37Microsoft traffic profile · possible, not confirmedIn Microsoft 365 SharePoint endpoint set 37 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
shellprod. |
TCP 443 | Microsoft 365 content deliveryEndpoint set 70; the set gives no per-host purpose. | PublishedMicrosoft 365 URLs and IP address ranges · set 70Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 70 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
spoprod-a. |
TCP 80, 443 | SharePoint content deliveryEndpoint set 37. | PublishedMicrosoft 365 URLs and IP address ranges · set 37Microsoft traffic profile · possible, not confirmedIn Microsoft 365 SharePoint endpoint set 37 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP/UDP 443 | Static Microsoft 365 content on CDNsThe live API publishes it in set 193; the Unified Domains table on the page labels it 184. | PublishedMicrosoft 365 URLs and IP address ranges · set 193Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 193 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP/UDP 443 | Microsoft 365 content that needs domain isolationThe live API publishes it in set 193; the Unified Domains table on the page labels it 184. | PublishedMicrosoft 365 URLs and IP address ranges · set 193Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 193 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
admin.optional |
TCP 443 | Exchange admin center (direct address)From an older page; current Exchange guidance uses admin.cloud.microsoft/exchange. Not in the Microsoft 365 endpoint list except under the optional *.microsoft.com wildcard. | PublishedFeatures in the new Exchange admin centerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
compliance.optional |
TCP 443 | Legacy compliance portalEndpoint set 64 (required within the set). | PublishedMicrosoft 365 URLs and IP address ranges · set 64Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
defender.optional |
TCP 443 | Microsoft Defender portal (alternate address)Endpoint set 64 (required within the set). | PublishedMicrosoft 365 URLs and IP address ranges · set 64Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*.optional |
TCP 443 | Microsoft Defender for Cloud Apps portalEndpoint set 66 (required within the set). | PublishedMicrosoft 365 URLs and IP address ranges · set 66Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 66 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www.optional |
TCP 80, 443 | Microsoft 365 home pageEndpoint set 147. | PublishedMicrosoft 365 URLs and IP address ranges · set 147Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
Probably taken before Internet Access10public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
13. |
TCP 443 | Common endpoint set 64 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
13. |
TCP 443 | Common endpoint set 64 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
2620:1ec:4::192/ |
TCP 443 | Common endpoint set 64 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
2620:1ec:a92::192/ |
TCP 443 | Common endpoint set 64 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
admin. |
TCP 443 | Teams admin centerStated in the page introduction, which has no anchor. Covered by *.teams.microsoft.com (endpoint set 12). | PublishedManage teams in the Microsoft Teams admin centerMicrosoft traffic profile · indicated, not confirmedIn Microsoft 365 Teams / Skype endpoint set 12 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Common endpoint set 64 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
protection. |
TCP 443 | Common endpoint set 64 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 64 · set 64Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Common endpoint set 64 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | SharePoint Online, including the tenant admin centerEndpoint set 31 (also UDP 443). Allows every tenant's SharePoint; prefer the tenant-specific host where your filter allows it. | PublishedMicrosoft 365 URLs and IP address ranges · set 31Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 SharePoint endpoint set 31 (Optimize category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Teams service and admin APIsEndpoint set 12; its media IP ranges and UDP ports aren't needed for administration. | PublishedMicrosoft 365 URLs and IP address ranges · set 12Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 Teams / Skype endpoint set 12 (Allow category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
{tenant}-admin.optional |
TCP 443 | SharePoint admin center for your tenantA narrower alternative to *.sharepoint.com. | CuratedGet started with the SharePoint Online Management ShellPlaceholder form of the page's examples https://contoso-admin.sharepoint.com and https://tenant-admin.sharepoint.com.Microsoft traffic profile · indicated, not confirmedIn Microsoft 365 SharePoint endpoint set 31 (Optimize category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |