Windows 365 and Azure Virtual Desktop
What an end-user device needs to connect to Cloud PCs and Azure Virtual Desktop sessions with Windows App, the Remote Desktop clients or the web client. The Cloud PCs and session hosts have their own, longer list.
Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Windows 365 · Azure Virtual Desktop
Managed device because the list applies to the physical device that connects, not to the Cloud PC or session host. Windows 365 points physical devices at the Azure Virtual Desktop end-user list, so one bundle covers both services. Microsoft says blocking these isn't supported; only the documentation and privacy statement links are optional here. The page also sends you to Microsoft 365 endpoint sets 46, 56, 59 and 125 for Microsoft Entra; 56, 59 and 125 are merged, and 46 (Office Online) is left out because it isn't an identity set. Azure cloud tab only; US Government hosts differ.
Cited pages since the review
4 of 4 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint data| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 95 | 0 | Open |
| GSA V1 domain list | 78 | 17 | Open |
| GSA V1 Graph request body | 78 | 17 | Download |
| GSA V2 rules (review JSON) | 78 | 17 | Download |
| GSA V2 rules (CSV) | 78 | 17 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/windows-365-avd. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle windows-365-avd from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Expected to reach web filtering4expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
51. |
UDP 3478 | Relayed RDP connectivity (RDP Shortpath through TURN)All clients. Without it, connections fall back to TCP through the gateway, which works but with higher latency. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
azcsprodeusaikpublish. |
TCP 80 | CertificatesPlain HTTP. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 80 | CertificatesPlain HTTP. The name points to TPM attestation identity key (AIK) certificates; Microsoft labels it only 'Certificates'. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
*. |
TCP 443 | Troubleshooting dataAll clients. A broad shared Azure namespace; review it before allowing it on a locked-down device. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
Not determined43public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
*. |
TCP 80 | CertificatesPlain HTTP. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
aka. |
TCP 443 | Microsoft URL shortenerAll clients. | PublishedRequired FQDNs and endpoints for Azure Virtual Desktop · set 17Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cacerts. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Automatic client updatesWindows Desktop client only; not needed if client updates are delivered another way. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 47 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
cert. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl3. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
crl4. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ecs. |
TCP 443 | Connection centerAll clients. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Client telemetryAll clients. Listed in the required end-user table, although the session host table calls the same host optional. | PublishedRequired FQDNs and endpoints for Azure Virtual Desktop · set 69Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
go. |
TCP 443 | Microsoft FWLinksAll clients. | PublishedRequired FQDNs and endpoints for Azure Virtual Desktop · set 89Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
graph. |
TCP 443 | Service trafficAll clients. Also Microsoft 365 endpoint set 56. | PublishedRequired FQDNs and endpoints for Azure Virtual Desktop · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
isrg. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
login. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
mscrl. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocsp2. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
ocspx. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
oneocsp. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
secure. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Service trafficAll clients. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Service trafficAll clients. Doesn't match windows.cloud.microsoft itself, which is listed separately. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
windows. |
TCP 443 | Connection center (web client and Windows App)All clients. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Service traffic (static content)All clients. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 193 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
windows365. |
TCP 443 | Windows 365 service trafficAll clients. Microsoft publishes only this bare name for devices; *.infra.windows365.microsoft.com is a Cloud PC network requirement, not a device one. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Azure Virtual Desktop service trafficAll clients. The session host table lists the same wildcard for TCP-based RDP connectivity. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80, 443 | Common endpoint set 125 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 125 · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
www. |
TCP 80 | CertificatesPlain HTTP for certificate retrieval and revocation. The page adds that closed networks may also need the hosts in the certificate-revocation bundle. | PublishedRequired FQDNs and endpoints for Azure Virtual Desktop · set 125Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
learn.optional |
TCP 443 | Documentation linksMicrosoft lists it in the required table; marked optional here because it only serves help links. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
privacy.optional |
TCP 443 | Privacy statement linkMicrosoft lists it in the required table; marked optional here because it only serves the privacy statement. | PublishedRequired FQDNs and endpoints for Azure Virtual DesktopMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
Probably taken before Internet Access48public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
20. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
20. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
20. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1006:2000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1007:200::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1016:1400::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1017::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1026:3000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1027:1::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1036:3000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1037:1::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1046:2000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1047:1::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1056:2000::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
2603:1057:2::/ |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
40. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
account. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
accounts. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
adminwebservice. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
api. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
autologon. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
becws. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
ccs. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
clientconfig. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
companymanager. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
device. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
enterpriseregistration. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
graph. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login-us. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 443 | Authentication to Microsoft Online ServicesAll clients. Also Microsoft 365 endpoint set 56. | PublishedRequired FQDNs and endpoints for Azure Virtual Desktop · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
login. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
logincert. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
loginex. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
nexus. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
passwordreset. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
*. |
TCP 80, 443 | Common endpoint set 59 (Default) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 59 · set 59Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 59, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
provisioningapi. |
TCP 80, 443 | Common endpoint set 56 (Allow) | PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 56 · set 56Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |
Also published
Material the publisher keeps current that is not copied here- Windows 365 network requirements: Allow network connectivity
- Required FQDNs and endpoints for Azure Virtual Desktop: session host virtual machines
- Windows 365 network requirements: Windows 365 service (Cloud PC provisioning and health checks)
- Check access to required FQDNs and endpoints for Azure Virtual Desktop (Azure Virtual Desktop Agent URL Tool)
- Use Azure Firewall to manage and secure Windows 365 environments (FQDN tags)