Action Required: Update firewall configurations to include new Intune network endpoints
By December 2, 2025, update firewall rules to include new Azure Front Door IP ranges (tagged “AzureFrontDoor.MicrosoftSecurity”) for Microsoft Intune. This ensures uninterrupted device and app management connectivity. Keep existing Intune endpoints and notify your IT/network team to implement these changes. As part of Microsoft’s ongoing Secure Future Initiative (SFI), starting on or shortly after December 2, 2025, the network service endpoints for Microsoft Intune will also use the Azure Front Door IP addresses. This improvement supports better alignment with modern security practices and over time will make it easier for organizations using multiple Microsoft products to manage and maintain their firewall configurations. As a result, customers may be required to add these network (firewall) configurations in third-party applications to enable proper function of Intune device and app management. This change will affect customers using a firewall allowlist that allows outbound traffic based on IP addresses or Azure service tags. Do not remove any existing network endpoints required for Microsoft Intune. Additional network endpoints are documented as part of the Azure Front Door and service tags information referenced in the files linked below: Public clouds: Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center Government clouds: Download Azure IP Ranges and Service Tags – US Government Cloud from Official Microsoft Download Center The additional ranges are those listed in the JSON files linked above and can be found by searching for “AzureFrontDoor.MicrosoftSecurity”. How this will affect your organization: If you have configured an outbound traffic policy for Intune IP address ranges or Azure service tags for your firewalls, routers, proxy servers, client-based firewalls, VPN or network security groups, you will need to update them to include the new Azure Front Door ranges with the “AzureFrontDoor.MicrosoftSecurity” tag. Intune requires internet access for devices under Intune management, whether for mobile device management or mobile application management. If your outbound traffic policy doesn’t include the new Azure Front Door IP address ranges, users may face login issues, devices might lose connectivity with Intune, and access to apps like the Intune Company Portal or those protected by app protection policies […]
The post Action Required: Update firewall configurations to include new Intune network endpoints appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Action Required: Update firewall configurations to include new Intune network endpoints
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Preparing the Windows ecosystem for next-generation code signing
Rollout schedule: Microsoft guidance is already available. October 19, 2026: Microsoft Windows Production PCA 2011 expires. End of 2026: Windo...
Microsoft Viva: Viva Learning retirement of Microsoft 365 training content
Microsoft is retiring 161 Microsoft 365 training modules and selected articles from Viva Learning on September 21, 2026, removing outdated con...
Improved capabilities for files with Copilot in OneDrive Web
Copilot in OneDrive Web enables users with a Microsoft 365 Copilot license to find, understand, analyze, create, and act on files using natura...
Microsoft Teams: Prepare custom apps for private and shared channel compatibility
Microsoft Teams will roll out a feature by September 2026 to help admins identify custom line-of-business apps needing updates for private and...
Microsoft Entra ID: Passkey support for B2B users
Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing re...
Microsoft 365 admin center: Usage reports migrating to new domains
Microsoft 365 admin center Usage reports domains will change starting mid-August 2026, with current and new domains active in parallel for at ...
Microsoft Teams: Local Pan-tilt-zoom (PTZ) controls for Microsoft Teams Rooms on Windows
Microsoft Teams Rooms on Windows will add native local Pan-Tilt-Zoom (PTZ) camera controls for compatible mechanical or optical PTZ cameras, a...
New in Microsoft 365 Copilot: Self-serve Copilot Connectors
Microsoft 365 Copilot now offers self-serve connectors, allowing users to securely sync external data like Jira and Confluence with their cred...
Microsoft Teams: Admin policy to automatically block identified external meeting bots from joining meetings
Microsoft Teams will introduce a new admin policy, starting August 2026, allowing automatic blocking of identified external meeting bots from ...
Microsoft 365 Copilot: Personalized Copilot Suggestions Coming to Frontier
Microsoft 365 Copilot will introduce personalized AI suggestions in Copilot Chat for eligible Frontier program users starting early August 202...