182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

PowerShell modules and admin sign-in

Install and update modules from the PowerShell Gallery, then sign in with Microsoft Graph PowerShell, Microsoft Entra PowerShell or Exchange Online PowerShell.

Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · PowerShell · PSResourceGet · Microsoft Graph PowerShell SDK · Entra PowerShell · Exchange Online PowerShell

Microsoft publishes the Gallery host list. The sign-in and API hosts come from the Microsoft 365 endpoint list; Microsoft doesn't publish a separate network list for the Graph, Entra or Exchange Online PowerShell modules. The old azureedge.net Gallery endpoints are no longer supported.

Cited pages since the review

3 of 3 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data
FormatDestinationsLeft outDownload
Plain list, one per line110 Open
GSA V1 domain list101 Open
GSA V1 Graph request body110 Download
GSA V2 rules (review JSON)110 Download
GSA V2 rules (CSV)110 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/powershell-modules. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle powershell-modules from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Expected to reach web filtering4expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
DestinationPortsPurposeEvidence
cdn.oneget.org TCP 443 PackageManagement (OneGet) CDN, including the NuGet provider bootstrapReplaces onegetcdn.azureedge.net. PublishedGet Started with the PowerShell Gallery
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

cdn.powershellgallery.com TCP 443 PowerShell Gallery package discovery and downloadPort isn't stated; the Gallery requires TLS 1.2 over HTTPS. PublishedGet Started with the PowerShell Gallery
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.powershellgallery.com TCP 443 PowerShell Gallery website and the registered PSGallery repository hostMicrosoft labels it as the website host. The default PSGallery repository URI is https://www.powershellgallery.com/api/v2, so module installs also reach it. PublishedGet Started with the PowerShell Gallery
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

https://www.powershellgallery.com/api/v2optional TCP 443 Default PSGallery repository endpoint used by PowerShellGet and PSResourceGetFor path-aware proxies; *.powershellgallery.com already covers the host. PublishedGet-PSResourceRepository
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

Not determined3public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
go.microsoft.com TCP 443 Redirection service used by the PowerShell GalleryAlso Microsoft 365 endpoint set 89 (Common). PublishedGet Started with the PowerShell Gallery · set 89
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

graph.microsoft.com TCP 80, 443 Microsoft Graph API called by Microsoft Graph PowerShell and Microsoft Entra PowerShellEndpoint set 56. The Entra PowerShell install page names no endpoints; it's built on the Microsoft Graph SDK. PublishedMicrosoft 365 URLs and IP address ranges · set 56
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

aka.msoptional TCP 443 Short-link redirection service used by the PowerShell Gallery websiteAlso Microsoft 365 endpoint set 17 (Teams). PublishedGet Started with the PowerShell Gallery · set 17
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access4public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
login.microsoftonline.com TCP 80, 443 Microsoft Entra sign-in for Connect-MgGraph, Connect-Entra and Connect-ExchangeOnlineEndpoint set 56. Get-MgEnvironment names it as the global Entra endpoint. PublishedMicrosoft 365 URLs and IP address ranges · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.msauth.net TCP 80, 443 Identity supporting services and CDNs for interactive sign-inEndpoint set 59; Microsoft doesn't tie it to PowerShell specifically. PublishedMicrosoft 365 URLs and IP address ranges · set 59
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

*.msftauth.net TCP 80, 443 Identity supporting services and CDNs for interactive sign-inEndpoint set 59; Microsoft doesn't tie it to PowerShell specifically. PublishedMicrosoft 365 URLs and IP address ranges · set 59
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

outlook.office365.comoptional TCP 443 Exchange Online PowerShell connection endpointEndpoint set 1. Connect-ExchangeOnline -ConnectionUri defaults to https://outlook.office365.com/powershell-liveid/. Needed only for Exchange Online PowerShell. PublishedMicrosoft 365 URLs and IP address ranges · set 1
Microsoft traffic profile · indicated, not confirmed

In Microsoft 365 Exchange endpoint set 1 (Optimize category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current