You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/dev-box/concept-dev-box-network-requirements.md
+48-48Lines changed: 48 additions & 48 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -70,39 +70,39 @@ Managing network security controls for dev boxes can be complex. To simplify con
70
70
## Required endpoints for physical device network connectivity
71
71
Although most of the configuration is for the cloud-based dev box network, end user connectivity occurs from a physical device. Therefore, you must also follow the connectivity guidelines on the physical device network.
72
72
73
-
|Device or service |Network connectivity required URLs and ports |Description |
74
-
|---|---|---|
75
-
|Physical device |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#remote-desktop-clients)|Remote Desktop client connectivity and updates.|
76
-
|Microsoft Intune service |[Link](/mem/intune/fundamentals/intune-endpoints)|Intune cloud services like device management, application delivery, and endpoint analytics.|
77
-
|Azure Virtual Desktop session host virtual machine |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#session-host-virtual-machines)|Remote connectivity between dev boxes and the backend Azure Virtual Desktop service.|
78
-
|Windows 365 service |[Link](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service)|Provisioning and health checks.|
73
+
|Device or service |Network connectivity required URLs and ports |Description | Required? |
74
+
|---|---|---| --- |
75
+
|Physical device |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#remote-desktop-clients)|Remote Desktop client connectivity and updates.| Yes |
76
+
|Microsoft Intune service |[Link](/mem/intune/fundamentals/intune-endpoints)|Intune cloud services like device management, application delivery, and endpoint analytics.| Yes |
77
+
|Azure Virtual Desktop session host virtual machine |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#session-host-virtual-machines)|Remote connectivity between dev boxes and the backend Azure Virtual Desktop service.| Yes |
78
+
|Windows 365 service |[Link](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service)|Provisioning and health checks.| Yes |
79
79
80
80
Any device you use to connect to a dev box must have access to the following FQDNs and endpoints. Allowing these FQDNs and endpoints is essential for a reliable client experience. Blocking access to these FQDNs and endpoints is unsupported and affects service functionality.
81
81
82
-
|Address |Protocol |Outbound port |Purpose |Clients |
83
-
|---|---|---|---|---|
84
-
|login.microsoftonline.com |TCP |443 |Authentication to Microsoft Online Services |All |
|query.prod.cms.rt.microsoft.com |TCP |443 |Download an MSI to update the client. Required for automatic updates. |Windows Desktop | Yes |
92
92
93
93
These FQDNs and endpoints only correspond to client sites and resources.
94
94
95
95
## Required endpoints for dev box provisioning
96
96
97
97
The following URLs and ports are required for the provisioning of dev boxes and the Azure Network Connection (ANC) health checks. All endpoints connect over port 443 unless otherwise specified.
98
98
99
-
| Category | Endpoints | FQDN tag or Service tag |
|**Dev box communication endpoints**|*.agentmanagement.dc.azure.com<br>*.cmdagent.trafficmanager.net | N/A |
102
-
|**Windows 365 service and registration endpoints**| For current Windows 365 registration endpoints, see [Windows 365 network requirements](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service). | FQDN tag: *Windows365*|
103
-
|**Azure Virtual Desktop service endpoints**| For current AVD service endpoints, see [Session host virtual machines](/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#session-host-virtual-machines). | FQDN tag: *WindowsVirtualDesktop*|
104
-
|**Microsoft Entra ID**| FQDNs and endpoints for Microsoft Entra ID can be found under ID 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online). | Service tag: *AzureActiveDirectory*|
105
-
|**Microsoft Intune**| For current FQDNs and endpoints for Microsoft Entra ID, see [Intune core service](/mem/intune/fundamentals/intune-endpoints?tabs=north-america#intune-core-service).| FQDN tag: *MicrosoftIntune*|
99
+
| Category | Endpoints | FQDN tag or Service tag | Required? |
|**Dev box communication endpoints**|*.agentmanagement.dc.azure.com<br>*.cmdagent.trafficmanager.net | N/A | Yes |
102
+
|**Windows 365 service and registration endpoints**| For current Windows 365 registration endpoints, see [Windows 365 network requirements](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service). | FQDN tag: *Windows365*| Yes |
103
+
|**Azure Virtual Desktop service endpoints**| For current AVD service endpoints, see [Session host virtual machines](/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#session-host-virtual-machines). | FQDN tag: *WindowsVirtualDesktop*| Yes |
104
+
|**Microsoft Entra ID**| FQDNs and endpoints for Microsoft Entra ID can be found under ID 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online). | Service tag: *AzureActiveDirectory*| Yes |
105
+
|**Microsoft Intune**| For current FQDNs and endpoints for Microsoft Entra ID, see [Intune core service](/mem/intune/fundamentals/intune-endpoints?tabs=north-america#intune-core-service).| FQDN tag: *MicrosoftIntune*| Yes |
106
106
107
107
The listed FQDNs and endpoints and tags correspond to the required resources. They don't include FQDNs and endpoints for all services. For service tags for other services, see [Available service tags](/azure/virtual-network/service-tags-overview#available-service-tags).
108
108
@@ -112,34 +112,34 @@ For more information, see [Use Azure Firewall to manage and secure Windows 365 e
112
112
113
113
The following table is the list of FQDNs and endpoints your dev boxes need to access. All entries are outbound; you don't need to open inbound ports for dev boxes.
114
114
115
-
|Address |Protocol |Outbound port |Purpose |Service tag|
116
-
|---|---|---|---|---|
117
-
|login.microsoftonline.com |TCP |443 |Authentication to Microsoft Online Services | AzureActiveDirectory |
|*.azure-dns.com |TCP |443 |Azure DNS resolution| Optional |
142
+
|*.azure-dns.net |TCP |443 |Azure DNS resolution| Optional |
143
143
144
144
This list doesn't include FQDNs and endpoints for other services such as Microsoft Entra ID, Office 365, custom DNS providers, or time services. Microsoft Entra FQDNs and endpoints can be found under ID 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online).
0 commit comments