Skip to content

Commit be3627b

Browse files
authored
Merge pull request #292159 from tanmayeekamath/patch-2
Update concept-dev-box-network-requirements.md
2 parents a0ebb83 + 8598eee commit be3627b

File tree

1 file changed

+48
-48
lines changed

1 file changed

+48
-48
lines changed

articles/dev-box/concept-dev-box-network-requirements.md

Lines changed: 48 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -70,39 +70,39 @@ Managing network security controls for dev boxes can be complex. To simplify con
7070
## Required endpoints for physical device network connectivity
7171
Although most of the configuration is for the cloud-based dev box network, end user connectivity occurs from a physical device. Therefore, you must also follow the connectivity guidelines on the physical device network.
7272

73-
|Device or service |Network connectivity required URLs and ports |Description |
74-
|---|---|---|
75-
|Physical device |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#remote-desktop-clients) |Remote Desktop client connectivity and updates.|
76-
|Microsoft Intune service |[Link](/mem/intune/fundamentals/intune-endpoints) |Intune cloud services like device management, application delivery, and endpoint analytics.|
77-
|Azure Virtual Desktop session host virtual machine |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#session-host-virtual-machines) |Remote connectivity between dev boxes and the backend Azure Virtual Desktop service.|
78-
|Windows 365 service |[Link](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service) |Provisioning and health checks.|
73+
|Device or service |Network connectivity required URLs and ports |Description | Required? |
74+
|---|---|---| --- |
75+
|Physical device |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#remote-desktop-clients) |Remote Desktop client connectivity and updates.| Yes |
76+
|Microsoft Intune service |[Link](/mem/intune/fundamentals/intune-endpoints) |Intune cloud services like device management, application delivery, and endpoint analytics.| Yes |
77+
|Azure Virtual Desktop session host virtual machine |[Link](/azure/virtual-desktop/safe-url-list?tabs=azure#session-host-virtual-machines) |Remote connectivity between dev boxes and the backend Azure Virtual Desktop service.| Yes |
78+
|Windows 365 service |[Link](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service) |Provisioning and health checks.| Yes |
7979

8080
Any device you use to connect to a dev box must have access to the following FQDNs and endpoints. Allowing these FQDNs and endpoints is essential for a reliable client experience. Blocking access to these FQDNs and endpoints is unsupported and affects service functionality.
8181

82-
|Address |Protocol |Outbound port |Purpose |Clients |
83-
|---|---|---|---|---|
84-
|login.microsoftonline.com |TCP |443 |Authentication to Microsoft Online Services |All |
85-
|*.wvd.microsoft.com |TCP |443 |Service traffic |All |
86-
|*.servicebus.windows.net |TCP |443 |Troubleshooting data |All |
87-
|go.microsoft.com |TCP |443 |Microsoft FWLinks |All |
88-
|aka.ms |TCP |443 |Microsoft URL shortener |All |
89-
|learn.microsoft.com |TCP |443 |Documentation |All |
90-
|privacy.microsoft.com |TCP |443 |Privacy statement |All |
91-
|query.prod.cms.rt.microsoft.com |TCP |443 |Download an MSI to update the client. Required for automatic updates. |Windows Desktop |
82+
|Address |Protocol |Outbound port |Purpose |Clients | Required? |
83+
|---|---|---|---|---|---|
84+
|login.microsoftonline.com |TCP |443 |Authentication to Microsoft Online Services |All | Yes |
85+
|*.wvd.microsoft.com |TCP |443 |Service traffic |All | Yes |
86+
|*.servicebus.windows.net |TCP |443 |Troubleshooting data |All | Yes |
87+
|go.microsoft.com |TCP |443 |Microsoft FWLinks |All | Yes |
88+
|aka.ms |TCP |443 |Microsoft URL shortener |All | Yes |
89+
|learn.microsoft.com |TCP |443 |Documentation |All | Yes |
90+
|privacy.microsoft.com |TCP |443 |Privacy statement |All | Yes |
91+
|query.prod.cms.rt.microsoft.com |TCP |443 |Download an MSI to update the client. Required for automatic updates. |Windows Desktop | Yes |
9292

9393
These FQDNs and endpoints only correspond to client sites and resources.
9494

9595
## Required endpoints for dev box provisioning
9696

9797
The following URLs and ports are required for the provisioning of dev boxes and the Azure Network Connection (ANC) health checks. All endpoints connect over port 443 unless otherwise specified.
9898

99-
| Category | Endpoints | FQDN tag or Service tag |
100-
|---------------------------------|--------------------------------|-------------------------------------|
101-
| **Dev box communication endpoints** | *.agentmanagement.dc.azure.com<br>*.cmdagent.trafficmanager.net | N/A |
102-
| **Windows 365 service and registration endpoints** | For current Windows 365 registration endpoints, see [Windows 365 network requirements](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service). | FQDN tag: *Windows365* |
103-
| **Azure Virtual Desktop service endpoints** | For current AVD service endpoints, see [Session host virtual machines](/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#session-host-virtual-machines). | FQDN tag: *WindowsVirtualDesktop* |
104-
| **Microsoft Entra ID** | FQDNs and endpoints for Microsoft Entra ID can be found under ID 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online). | Service tag: *AzureActiveDirectory* |
105-
| **Microsoft Intune** | For current FQDNs and endpoints for Microsoft Entra ID, see [Intune core service](/mem/intune/fundamentals/intune-endpoints?tabs=north-america#intune-core-service).| FQDN tag: *MicrosoftIntune* |
99+
| Category | Endpoints | FQDN tag or Service tag | Required? |
100+
|---------------------------------|--------------------------------|-------------------------------------|-------------------------------------|
101+
| **Dev box communication endpoints** | *.agentmanagement.dc.azure.com<br>*.cmdagent.trafficmanager.net | N/A | Yes |
102+
| **Windows 365 service and registration endpoints** | For current Windows 365 registration endpoints, see [Windows 365 network requirements](/windows-365/enterprise/requirements-network?tabs=enterprise%2Cent#windows-365-service). | FQDN tag: *Windows365* | Yes |
103+
| **Azure Virtual Desktop service endpoints** | For current AVD service endpoints, see [Session host virtual machines](/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#session-host-virtual-machines). | FQDN tag: *WindowsVirtualDesktop* | Yes |
104+
| **Microsoft Entra ID** | FQDNs and endpoints for Microsoft Entra ID can be found under ID 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online). | Service tag: *AzureActiveDirectory* | Yes |
105+
| **Microsoft Intune** | For current FQDNs and endpoints for Microsoft Entra ID, see [Intune core service](/mem/intune/fundamentals/intune-endpoints?tabs=north-america#intune-core-service).| FQDN tag: *MicrosoftIntune* | Yes |
106106

107107
The listed FQDNs and endpoints and tags correspond to the required resources. They don't include FQDNs and endpoints for all services. For service tags for other services, see [Available service tags](/azure/virtual-network/service-tags-overview#available-service-tags).
108108

@@ -112,34 +112,34 @@ For more information, see [Use Azure Firewall to manage and secure Windows 365 e
112112

113113
The following table is the list of FQDNs and endpoints your dev boxes need to access. All entries are outbound; you don't need to open inbound ports for dev boxes.
114114

115-
|Address |Protocol |Outbound port |Purpose |Service tag|
116-
|---|---|---|---|---|
117-
|login.microsoftonline.com |TCP |443 |Authentication to Microsoft Online Services | AzureActiveDirectory |
118-
|*.wvd.microsoft.com |TCP |443 |Service traffic |WindowsVirtualDesktop |
119-
|*.prod.warm.ingest.monitor.core.windows.net |TCP |443 |Agent traffic [Diagnostic output](/azure/virtual-desktop/diagnostics-log-analytics) |AzureMonitor |
120-
|catalogartifact.azureedge.net |TCP |443 |Azure Marketplace |AzureFrontDoor.Frontend|
121-
|gcs.prod.monitoring.core.windows.net |TCP |443 |Agent traffic |AzureCloud|
122-
|kms.core.windows.net |TCP |1688 |Windows activation |Internet|
123-
|azkms.core.windows.net |TCP |1688 |Windows activation |Internet|
124-
|mrsglobalsteus2prod.blob.core.windows.net |TCP |443 |Agent and side-by-side (SXS) stack updates |AzureCloud|
125-
|wvdportalstorageblob.blob.core.windows.net |TCP |443 |Azure portal support |AzureCloud|
126-
|169.254.169.254 |TCP |80 |[Azure Instance Metadata service endpoint](/azure/virtual-machines/windows/instance-metadata-service)|N/A|
127-
|168.63.129.16 |TCP |80 |[Session host health monitoring](/azure/virtual-network/network-security-groups-overview#azure-platform-considerations)|N/A|
128-
|oneocsp.microsoft.com |TCP |80 |Certificates |N/A|
129-
|www.microsoft.com |TCP |80 |Certificates |N/A|
115+
|Address |Protocol |Outbound port |Purpose |Service tag| Required? |
116+
|---|---|---|---|---|---|
117+
|login.microsoftonline.com |TCP |443 |Authentication to Microsoft Online Services | AzureActiveDirectory | Yes |
118+
|*.wvd.microsoft.com |TCP |443 |Service traffic |WindowsVirtualDesktop | Yes |
119+
|*.prod.warm.ingest.monitor.core.windows.net |TCP |443 |Agent traffic [Diagnostic output](/azure/virtual-desktop/diagnostics-log-analytics) |AzureMonitor | Yes |
120+
|catalogartifact.azureedge.net |TCP |443 |Azure Marketplace |AzureFrontDoor.Frontend| Yes |
121+
|gcs.prod.monitoring.core.windows.net |TCP |443 |Agent traffic |AzureCloud| Yes |
122+
|kms.core.windows.net |TCP |1688 |Windows activation |Internet| Yes |
123+
|azkms.core.windows.net |TCP |1688 |Windows activation |Internet| Yes |
124+
|mrsglobalsteus2prod.blob.core.windows.net |TCP |443 |Agent and side-by-side (SXS) stack updates |AzureCloud| Yes |
125+
|wvdportalstorageblob.blob.core.windows.net |TCP |443 |Azure portal support |AzureCloud| Yes |
126+
|169.254.169.254 |TCP |80 |[Azure Instance Metadata service endpoint](/azure/virtual-machines/windows/instance-metadata-service)|N/A| Yes |
127+
|168.63.129.16 |TCP |80 |[Session host health monitoring](/azure/virtual-network/network-security-groups-overview#azure-platform-considerations)|N/A| Yes |
128+
|oneocsp.microsoft.com |TCP |80 |Certificates |N/A| Yes |
129+
|www.microsoft.com |TCP |80 |Certificates |N/A| Yes |
130130

131131
The following table lists optional FQDNs and endpoints that your session host virtual machines might also need to access for other services:
132132

133-
|Address |Protocol |Outbound port |Purpose|
134-
|---|---|---|---|
135-
|login.windows.net |TCP |443 |Sign in to Microsoft Online Services and Microsoft 365|
136-
|*.events.data.microsoft.com |TCP |443 |Telemetry Service|
137-
|www.msftconnecttest.com |TCP |80 |Detects if the session host is connected to the internet|
138-
|*.prod.do.dsp.mp.microsoft.com |TCP |443 |Windows Update|
139-
|*.sfx.ms |TCP |443 |Updates for OneDrive client software|
140-
|*.digicert.com |TCP |80 |Certificate revocation check|
141-
|*.azure-dns.com |TCP |443 |Azure DNS resolution|
142-
|*.azure-dns.net |TCP |443 |Azure DNS resolution|
133+
|Address |Protocol |Outbound port |Purpose| Required? |
134+
|---|---|---|---|---|
135+
|login.windows.net |TCP |443 |Sign in to Microsoft Online Services and Microsoft 365| Optional |
136+
|*.events.data.microsoft.com |TCP |443 |Telemetry Service|Optional |
137+
|www.msftconnecttest.com |TCP |80 |Detects if the session host is connected to the internet| Optional |
138+
|*.prod.do.dsp.mp.microsoft.com |TCP |443 |Windows Update| Optional |
139+
|*.sfx.ms |TCP |443 |Updates for OneDrive client software| Optional |
140+
|*.digicert.com |TCP |80 |Certificate revocation check| Optional |
141+
|*.azure-dns.com |TCP |443 |Azure DNS resolution| Optional |
142+
|*.azure-dns.net |TCP |443 |Azure DNS resolution| Optional |
143143

144144
This list doesn't include FQDNs and endpoints for other services such as Microsoft Entra ID, Office 365, custom DNS providers, or time services. Microsoft Entra FQDNs and endpoints can be found under ID 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online).
145145

0 commit comments

Comments
 (0)