182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Windows Update and Microsoft Store

Windows Update, Delivery Optimization and the Microsoft Store for managed Windows devices, with optional Windows Autopatch hosts.

Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Windows · Windows Autopatch

Do not TLS-inspect the Delivery Optimization service (geo.prod.do.dsp.mp.microsoft.com and array*.prod.do.dsp.mp.microsoft.com use certificate pinning), and let byte-range requests through for Windows Update and Delivery Optimization content. Several update hosts are plain HTTP on port 80. The Windows 11 connection endpoints page is a capture of an idle device, not a requirements list.

Cited pages since the review

7 of 7 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data
FormatDestinationsLeft outDownload
Plain list, one per line320 Open
GSA V1 domain list311 Open
GSA V1 Graph request body311 Download
GSA V2 rules (review JSON)311 Download
GSA V2 rules (CSV)311 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/windows-update. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle windows-update from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Expected to reach web filtering2expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
DestinationPortsPurposeEvidence
img-prod-cms-rt-microsoft-com.akamaized.net TCP 443 Microsoft Store app image filesWin11 page: if blocked, apps cannot be installed or updated from the Store. Third-party CDN domain (akamaized.net). PublishedManage connection endpoints for Windows 11 Enterprise
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

payloadprod*.blob.core.windows.netoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). Mid-label wildcard; many firewalls/GSA cannot express it as written. PublishedConfigure your network (Windows Autopatch)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

Not determined29public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
adl.windows.com TCP 443 Windows compatibility database updatesWin11 page: HTTPS. Intune set 164 lists TCP 80, 443. PublishedManage connection endpoints for Windows 11 Enterprise · set 19
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Teams / Skype endpoint set 19 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

cdn.storeedgefd.dsx.mp.microsoft.com TCP 80, 443 Microsoft-hosted Win32 Store app fallback cache PublishedNetwork endpoints for Microsoft Intune
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

ctldl.windowsupdate.com TCP 80, 443 Automatic Root Certificates Update (CTL download)Certificates area: TLSv1.2/HTTPS/HTTP. Covered by *.windowsupdate.com; listed separately because blocking it breaks root/untrusted certificate list updates. PublishedManage connection endpoints for Windows 11 Enterprise
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.delivery.mp.microsoft.com TCP 80, 443 Windows Update, Microsoft Update and Store online servicesTroubleshooting: HTTPS; Win11: TLSv1.2/HTTPS/HTTP. Depends on login.live.com (device authentication). HTTP RANGE required. PublishedWindows Update issues troubleshooting
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

displaycatalog.mp.microsoft.com TCP 80, 443 Microsoft Store API (AppInstallManager) catalogWin11 page lists it as *displaycatalog.mp.microsoft.com (non-standard wildcard). Intune: SSL inspection not supported. PublishedNetwork endpoints for Microsoft Intune
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.dl.delivery.mp.microsoft.com TCP 80, 443 OS updates, patches and Store app downloads; DO metadataTroubleshooting page lists HTTP; Win11 page lists TLSv1.2/HTTPS/HTTP. Proxy must allow HTTP RANGE requests (#issues-related-to-httpproxy). PublishedWindows Update issues troubleshooting · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

dl.delivery.mp.microsoft.com TCP 80, 443 MEM endpoint set 164 (Default) PublishedMicrosoft 365 endpoint web service, Worldwide version 2026081400, set 164 · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.do.dsp.mp.microsoft.com TCP 443 Delivery Optimization client to cloud serviceDO ports table: 443 for client-to-cloud. Intune lists TCP 80, 443. Must bypass TLS inspection and must not alter client source IP (https://learn.microsoft.com/en-us/windows/deployment/do/delivery-optimization-proxy#endpoints-to-exempt-from-tls-inspection). Peer traffic uses TCP 7680 (LAN) and UDP 3544 Teredo (Group/Internet modes): #ports. PublishedConfigure Delivery Optimization (DO) for Windows · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

emdl.ws.microsoft.com TCP 80 Windows Update download endpointHTTP-only; page warns not to use HTTPS for HTTP endpoints. PublishedWindows Update issues troubleshooting
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

licensing.mp.microsoft.com TCP 80, 443 Store app licensing and Windows online activationAlso on Win11 page (Licensing area). Intune: SSL inspection not supported. PublishedNetwork endpoints for Microsoft Intune
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

login.live.com TCP 443 Device authentication / Microsoft account (Windows Update and Store depend on it)Win11 page says Windows Update endpoints depend on the Device authentication and Microsoft Account endpoints (login.live.com, HTTPS and TLSv1.2/HTTPS/HTTP). PublishedManage connection endpoints for Windows 11 Enterprise · set 97
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.prod.do.dsp.mp.microsoft.com TCP 80, 443 Delivery Optimization service for Windows Update downloadsTroubleshooting page: TLS 1.2; Win11 endpoints page: TLSv1.2/HTTPS/HTTP. Bypass TLS inspection for geo.prod.do.dsp.mp.microsoft.com and array*.prod.do.dsp.mp.microsoft.com (certificate pinning). PublishedWindows Update issues troubleshooting
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

purchase.md.mp.microsoft.com TCP 80, 443 Microsoft Store API purchase/acquisitionIntune: SSL inspection not supported. PublishedNetwork endpoints for Microsoft Intune
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

storecatalogrevocation.storequality.microsoft.com TCP 80, 443 Microsoft Store license revocation for malicious appsTLSv1.2/HTTPS/HTTP. PublishedManage connection endpoints for Windows 11 Enterprise
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

storeedgefd.dsx.mp.microsoft.com TCP 80, 443 Microsoft Store API front doorWin11 page lists it as HTTP. Intune: SSL inspection not supported. PublishedNetwork endpoints for Microsoft Intune
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

tsfe.trafficshaping.dsp.mp.microsoft.com TCP 80, 443 Windows Update content regulation / traffic shapingTroubleshooting: TLS 1.2; Win11: TLSv1.2/HTTPS/HTTP. PublishedWindows Update issues troubleshooting · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.update.microsoft.com TCP 80, 443 Windows Update / Microsoft Update serviceTroubleshooting: TLS 1.2; Win11: TLSv1.2/HTTPS/HTTP. PublishedWindows Update issues troubleshooting · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.windowsupdate.com TCP 80, 443 Windows Update / Microsoft Update payloads and metadataListed as HTTP on the troubleshooting and Win11 pages; port 80 is essential. Covers download.windowsupdate.com and *.download.windowsupdate.com (HTTP RANGE requests required) and ctldl.windowsupdate.com. PublishedWindows Update issues troubleshooting · set 164
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.api.cdp.microsoft.comoptional TCP 80, 443 Public update-check web API used by Windows and other productsWin11 page Windows Update area: TLSv1.2/HTTPS/HTTP. Includes msedge.api.cdp.microsoft.com (Edge update). PublishedManage connection endpoints for Windows 11 Enterprise
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

definitionupdates.microsoft.comoptional TCP 443 Microsoft Defender definition updatesListed under the Windows Update area; TLSv1.2. PublishedManage connection endpoints for Windows 11 Enterprise
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

device.autopatch.microsoft.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

devicelistenerprod.microsoft.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

devicelistenprod.eudb.microsoft.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). For tenants with billing addresses in the EU Data Boundary (instead of devicelistenerprod.microsoft.com). PublishedConfigure your network (Windows Autopatch)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

livetileedge.dsx.mp.microsoft.comoptional TCP 443 Microsoft Store app content loadingOnly needed when the Store app UI is used. PublishedManage connection endpoints for Windows 11 Enterprise
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

mmdcustomer.microsoft.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

mmdls.microsoft.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

services.autopatch.microsoft.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch)
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.webpubsub.azure.comoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch) · set 187
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Intune (MEM) endpoint set 187 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

win1910.ipv6.microsoft.comoptional — Delivery Optimization group peering across NATs (Teredo)Only for DownloadMode Group (2)/Internet (3) across NATs; Teredo uses UDP 3544. No port stated for the host. PublishedConfigure Delivery Optimization (DO) for Windows
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access1public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
login.windows.netoptional — Windows Autopatch serviceOnly for Windows Autopatch. Page gives no ports (proxy/firewall must support TLS 1.2). PublishedConfigure your network (Windows Autopatch) · set 56
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current