You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | login.microsoftonline.com |
46
-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | IP Address | 169.254.169.254, 168.63.129.16 |
47
-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | Service Tag | WindowsVirtualDesktop, AzureFrontDoor.Frontend, AzureMonitor |
45
+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN |`login.microsoftonline.com`|
46
+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | IP Address |`169.254.169.254`, `168.63.129.16`|
47
+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | Service Tag |`WindowsVirtualDesktop`, `AzureFrontDoor.Frontend`, `AzureMonitor`|
48
48
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP, UDP | 53 | IP Address | * |
49
-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | 20.118.99.224, 40.83.235.53 (azkms.core.windows.net) |
50
-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | 23.102.135.246 (kms.core.windows.net) |
51
-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | mrsglobalsteus2prod.blob.core.windows.net |
52
-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | wvdportalstorageblob.blob.core.windows.net |
53
-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | oneocsp.microsoft.com |
54
-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN |www.microsoft.com|
49
+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address |`20.118.99.224`, `40.83.235.53` (`azkms.core.windows.net`) |
50
+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address |`23.102.135.246` (`kms.core.windows.net`) |
51
+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN |`mrsglobalsteus2prod.blob.core.windows.net`|
52
+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN |`wvdportalstorageblob.blob.core.windows.net`|
53
+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN |`oneocsp.microsoft.com`|
54
+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN |`www.microsoft.com`|
55
55
56
56
# [Azure for US Government](#tab/azure-for-us-government)
57
57
58
58
| Name | Source type | Source | Protocol | Destination ports | Destination type | Destination |
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN Tag | WindowsUpdate, Windows Diagnostics, MicrosoftActiveProtectionService |
91
-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |*.events.data.microsoft.com|
92
-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |*.sfx.ms |
93
-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |*.digicert.com |
94
-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |*.azure-dns.com, *.azure-dns.net |
90
+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN Tag |`WindowsUpdate`, `Windows Diagnostics`, `MicrosoftActiveProtectionService`|
91
+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |`*.events.data.microsoft.com`|
92
+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |`*.sfx.ms`|
93
+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |`*.digicert.com`|
94
+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN |`*.azure-dns.com`, `*.azure-dns.net`|
95
95
96
96
> [!IMPORTANT]
97
97
> We recommend that you don't use TLS inspection with Azure Virtual Desktop. For more information, see the [proxy server guidelines](../virtual-desktop/proxy-server-support.md#dont-use-ssl-termination-on-the-proxy-server).
0 commit comments