Loading...

Reminder: Update firewall configurations to include new Intune network endpoints

Reminder: Update firewall configurations to include new Intune network endpoints

By December 2, 2025, update firewall configurations to include new Azure Front Door IP addresses for Microsoft Intune. Add the service tag “AzureFrontDoor.MicrosoftSecurity” to allow outbound traffic on port 443. Do not remove existing Intune endpoints to ensure uninterrupted device and app management. As mentioned in MC1147982, as part of Microsoft’s ongoing Secure Future Initiative (SFI), starting on or shortly after December 2, 2025, the network service endpoints for Microsoft Intune will also use the Azure Front Door IP addresses. This improvement supports better alignment with modern security practices and over time will make it easier for organizations using multiple Microsoft products to manage and maintain their firewall configurations. As a result, customers may be required to add these network (firewall) configurations in third-party applications to enable proper function of Intune device and app management. This change will affect customers using a firewall allowlist that allows outbound traffic based on IP addresses or Azure service tags. Do not remove any existing network endpoints required for Microsoft Intune. Additional network endpoints are documented as part of the Azure Front Door and service tags information referenced in the files linked below: Public clouds: Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center  Government clouds: Download Azure IP Ranges and Service Tags – US Government Cloud from Official Microsoft Download Center  The additional ranges are those listed in the JSON files linked above and can be found by searching for “AzureFrontDoor.MicrosoftSecurity”. How this will affect your organization: If you have configured an outbound traffic policy for Intune IP address ranges or Azure service tags for your firewalls, routers, proxy servers, client-based firewalls, VPN or network security groups, you will need to update them to include the new Azure Front Door ranges with the “AzureFrontDoor.MicrosoftSecurity” tag.  Intune requires internet access for devices under Intune management, whether for mobile device management or mobile application management. If your outbound traffic policy doesn’t include the new Azure Front Door IP address ranges, users may face login issues, devices might lose connectivity with Intune, and access to apps like the Intune Company Portal or […]

The post Reminder: Update firewall configurations to include new Intune network endpoints appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Reminder: Update firewall configurations to include new Intune network endpoints

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Change in sender email address for Copilot emails

Microsoft is updating the sender email for Copilot-related educational and enablement emails to [email protected] by mid-S...

1 day ago

Microsoft Purview: Information Protection – Auto-labeling simulation scale increase from 4 million to 20 million items

Microsoft Purview Information Protection increases auto-labeling simulation capacity from 4 million to 20 million items, expands SharePoint si...

1 day ago

Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes

Microsoft is updating how EWSAllowedAppIDs is applied in Exchange Online as part of EWS retirement starting October 1, 2026. Organizations usi...

1 day ago

IT resources to plan, prepare, and deploy Windows

New and updated resources are available whether you’re a seasoned IT pro or earlier in your career. Learn how to effectively roll out feature ...

1 day ago

[Whiteboard] Legacy Whiteboard migration to OneDrive

Microsoft Whiteboard is migrating from legacy Azure-based storage to OneDrive-backed storage. Migration must be completed by September 25, 202...

1 day ago

Microsoft Teams: Organize important resources in chats and channels

Microsoft Teams is introducing a new way to organize and access important resources in chats and channels. Users will be able to pin key conte...

2 days ago

Microsoft Teams: Analytics for desk utilization on Teams Pro Management portal

Teams admins can access utilization analytics for Teams bookable desks on Teams Pro Management portal, similar to analytics provided for meeti...

2 days ago

Outlook: Inline chat for email drafting

Instead of opening Copilot Chat every time you want to use Copilot to draft a message, this change introduces an inline chat component that st...

2 days ago

SharePoint: Changes to the FAQ web part authoring experience

The SharePoint FAQ web part will provide a standard, non-AI experience for manually creating, editing, and managing FAQs. The AI-assisted FAQ ...

2 days ago

Microsoft Teams: Multi-line call history tabs in the Calls app

Multi-line users get a redesigned call history experience that organizes activity by phone line. Call activity is organized into dedicated tab...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.