Skip to content

Commit 90e49e2

Browse files
committed
make all URLs data
1 parent 362e0a1 commit 90e49e2

File tree

1 file changed

+24
-24
lines changed

1 file changed

+24
-24
lines changed

articles/firewall/protect-azure-virtual-desktop.md

Lines changed: 24 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -42,30 +42,30 @@ Based on the Azure Virtual Desktop (AVD) [reference article](../virtual-desktop/
4242

4343
| Name | Source type | Source | Protocol | Destination ports | Destination type | Destination |
4444
| --------- | -------------------- | ------------------------------------- | -------- | ----------------- | ---------------- | --------------------------------- |
45-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | login.microsoftonline.com |
46-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | IP Address | 169.254.169.254, 168.63.129.16 |
47-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | Service Tag | WindowsVirtualDesktop, AzureFrontDoor.Frontend, AzureMonitor |
45+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `login.microsoftonline.com` |
46+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | IP Address | `169.254.169.254`, `168.63.129.16` |
47+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | Service Tag | `WindowsVirtualDesktop`, `AzureFrontDoor.Frontend`, `AzureMonitor` |
4848
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP, UDP | 53 | IP Address | * |
49-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | 20.118.99.224, 40.83.235.53 (azkms.core.windows.net) |
50-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | 23.102.135.246 (kms.core.windows.net) |
51-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | mrsglobalsteus2prod.blob.core.windows.net |
52-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | wvdportalstorageblob.blob.core.windows.net |
53-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | oneocsp.microsoft.com |
54-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | www.microsoft.com |
49+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | `20.118.99.224`, `40.83.235.53` (`azkms.core.windows.net`) |
50+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | `23.102.135.246` (`kms.core.windows.net`) |
51+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `mrsglobalsteus2prod.blob.core.windows.net` |
52+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `wvdportalstorageblob.blob.core.windows.net` |
53+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | `oneocsp.microsoft.com` |
54+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | `www.microsoft.com` |
5555

5656
# [Azure for US Government](#tab/azure-for-us-government)
5757

5858
| Name | Source type | Source | Protocol | Destination ports | Destination type | Destination |
5959
| --------- | -------------------- | ------------------------------------- | -------- | ----------------- | ---------------- | --------------------------------- |
60-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | login.microsoftonline.us |
61-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | Service Tag | WindowsVirtualDesktop, AzureMonitor |
60+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `login.microsoftonline.us` |
61+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | Service Tag | `WindowsVirtualDesktop`, `AzureMonitor` |
6262
|Rule Name|IP Address or Group|IP Group or VNet or Subnet IP Address|TCP|443|FQDN|gcs.monitoring.core.usgovcloudapi.net|
6363
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP, UDP | 53 | IP Address | * |
64-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | kms.core.usgovcloudapi.net|
65-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | mrsglobalstugviffx.blob.core.usgovcloudapi.net |
66-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | wvdportalstorageblob.blob.core.usgovcloudapi.net |
67-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | IP Address | 169.254.169.254, 168.63.129.16 |
68-
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | ocsp.msocsp.com |
64+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 1688 | IP address | `kms.core.usgovcloudapi.net`|
65+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `mrsglobalstugviffx.blob.core.usgovcloudapi.net` |
66+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `wvdportalstorageblob.blob.core.usgovcloudapi.net` |
67+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | IP Address | `169.254.169.254`, `168.63.129.16` |
68+
| Rule name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 80 | FQDN | `ocsp.msocsp.com` |
6969

7070
---
7171

@@ -76,9 +76,9 @@ Azure Virtual Desktop (AVD) official documentation reports the following Network
7676

7777
| Name | Source type | Source | Protocol | Destination ports | Destination type | Destination |
7878
| ----------| -------------------- | ------------------------------------- | -------- | ----------------- | ---------------- | --------------------------------- |
79-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | UDP | 123 | FQDN | time.windows.com |
80-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | login.windows.net |
81-
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | www.msftconnecttest.com |
79+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | UDP | 123 | FQDN | `time.windows.com` |
80+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `login.windows.net` |
81+
| Rule Name | IP Address or Group | IP Group or VNet or Subnet IP Address | TCP | 443 | FQDN | `www.msftconnecttest.com` |
8282

8383

8484
### Create application rules
@@ -87,11 +87,11 @@ Azure Virtual Desktop (AVD) official documentation reports the following Applica
8787

8888
| Name | Source type | Source | Protocol | Destination type | Destination |
8989
| --------- | -------------------- | --------------------------| ---------- | ---------------- | ------------------------------------------------------------------------------------------- |
90-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN Tag | WindowsUpdate, Windows Diagnostics, MicrosoftActiveProtectionService |
91-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | *.events.data.microsoft.com |
92-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | *.sfx.ms |
93-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | *.digicert.com |
94-
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | *.azure-dns.com, *.azure-dns.net |
90+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN Tag | `WindowsUpdate`, `Windows Diagnostics`, `MicrosoftActiveProtectionService` |
91+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | `*.events.data.microsoft.com`|
92+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | `*.sfx.ms` |
93+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | `*.digicert.com` |
94+
| Rule Name | IP Address or Group | VNet or Subnet IP Address | Https:443 | FQDN | `*.azure-dns.com`, `*.azure-dns.net` |
9595

9696
> [!IMPORTANT]
9797
> We recommend that you don't use TLS inspection with Azure Virtual Desktop. For more information, see the [proxy server guidelines](../virtual-desktop/proxy-server-support.md#dont-use-ssl-termination-on-the-proxy-server).

0 commit comments

Comments
 (0)