Reminder: Update firewall configurations to include new Intune network endpoints
By December 2, 2025, update firewall configurations to include new Azure Front Door IP addresses for Microsoft Intune. Add the service tag “AzureFrontDoor.MicrosoftSecurity” to allow outbound traffic on port 443. Do not remove existing Intune endpoints to ensure uninterrupted device and app management. As mentioned in MC1147982, as part of Microsoft’s ongoing Secure Future Initiative (SFI), starting on or shortly after December 2, 2025, the network service endpoints for Microsoft Intune will also use the Azure Front Door IP addresses. This improvement supports better alignment with modern security practices and over time will make it easier for organizations using multiple Microsoft products to manage and maintain their firewall configurations. As a result, customers may be required to add these network (firewall) configurations in third-party applications to enable proper function of Intune device and app management. This change will affect customers using a firewall allowlist that allows outbound traffic based on IP addresses or Azure service tags. Do not remove any existing network endpoints required for Microsoft Intune. Additional network endpoints are documented as part of the Azure Front Door and service tags information referenced in the files linked below: Public clouds: Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center Government clouds: Download Azure IP Ranges and Service Tags – US Government Cloud from Official Microsoft Download Center The additional ranges are those listed in the JSON files linked above and can be found by searching for “AzureFrontDoor.MicrosoftSecurity”. How this will affect your organization: If you have configured an outbound traffic policy for Intune IP address ranges or Azure service tags for your firewalls, routers, proxy servers, client-based firewalls, VPN or network security groups, you will need to update them to include the new Azure Front Door ranges with the “AzureFrontDoor.MicrosoftSecurity” tag. Intune requires internet access for devices under Intune management, whether for mobile device management or mobile application management. If your outbound traffic policy doesn’t include the new Azure Front Door IP address ranges, users may face login issues, devices might lose connectivity with Intune, and access to apps like the Intune Company Portal or […]
The post Reminder: Update firewall configurations to include new Intune network endpoints appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Reminder: Update firewall configurations to include new Intune network endpoints
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Dynamics 365 Project Operations – Perform bulk operations for bookings on schedule board
We are announcing the ability to move or reassign multiple bookings at once, directly from the schedule board in Dynamics 365 Project Operatio...
Browser Use Admin Control for Copilot Cowork
Admins can now control browser use in Copilot Cowork via Microsoft 365 admin center, enabling access for specific users or groups. Rolling out...
Microsoft Copilot (Microsoft 365): Power BI reports as references in Copilot Notebooks
Copilot Notebooks now support adding Power BI reports as references, enhancing summaries with real business data. Public preview starts late S...
In-app browsing in Copilot app
Microsoft Copilot app now supports in-app browsing on Windows and Mac, allowing users to open websites side-by-side with chat. Available via a...
Updates available for Microsoft 365 Apps for Current Channel
We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...
Power Platform – Information regarding the end of support for Global Discovery Service (GDS) API
On September 21, 2026, the Global Discovery Service (GDS) API will have reached end of support. How does this affect me? The legacy Global Dis...
Microsoft Copilot: SpaceXAI subprocessor admin setting
SpaceXAI is added as a Microsoft Copilot subprocessor, enabling Grok models in Word, Excel, and PowerPoint for eligible Frontier customers sta...
Retirement of Microsoft 365 Companion apps
Microsoft 365 companion apps (Calendar, People, Files) will retire on December 16, 2026, ceasing support and functionality. Admins must stop n...
Microsoft Planner: Capacity view
Capacity view in Microsoft Planner, launching October 2026, shows a live staffing timeline from existing task data for Plan 3 users on web/des...
Microsoft Purview: Archive file classification behavior change for Endpoint Data Loss Prevention on Windows endpoints
Microsoft Purview Endpoint DLP on Windows will classify archive files (.zip, .rar) as single atomic objects, reporting only the outer archive ...