You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
description: A list of URLs you must unblock to ensure your Azure Virtual Desktop deployment works as intended.
4
4
author: Heidilohr
5
5
ms.topic: conceptual
6
-
ms.date: 05/26/2022
6
+
ms.date: 08/30/2022
7
7
ms.author: helohr
8
8
manager: femila
9
9
---
10
10
11
11
# Required URLs for Azure Virtual Desktop
12
12
13
-
In order to deploy and make Azure Virtual Desktop available to your users, you must allow specific URLs that your session host virtual machines (VMs) can access them anytime. Users also need to be able to connect to certain URLs to access their Azure Virtual Desktop resources. This article lists the required URLs you need to allow for your session hosts and users. Azure Virtual Desktop doesn't support deployments that block the URLs listed in this article.
13
+
In order to deploy and make Azure Virtual Desktop available to your users, you must allow specific URLs that your session host virtual machines (VMs) can access them anytime. Users also need to be able to connect to certain URLs to access their Azure Virtual Desktop resources. This article lists the required URLs you need to allow for your session hosts and users if you're using [Azure Firewall](../firewall/protect-azure-virtual-desktop.md) or a third-party firewall or proxy service. Azure Virtual Desktop doesn't support deployments that block the URLs listed in this article.
14
14
15
15
You can validate that your session host VMs can connect to these URLs by following the steps to run the [Required URL Check tool](required-url-check-tool.md). The Required URL Check tool will validate each URL and show whether your session host VMs can access them. You can only use for deployments in the Azure public cloud, it does not check access for sovereign clouds.
16
16
17
17
## Session host virtual machines
18
18
19
-
Below is the list of URLs your session host VMs need to access for Azure Virtual Desktop. Select the relevant tab based on which cloud you're using.
19
+
The following table is the list of URLs your session host VMs need to access for Azure Virtual Desktop. Select the relevant tab based on which cloud you're using.
20
20
21
21
# [Azure cloud](#tab/azure)
22
22
23
-
| Address | Outbound TCP port | Purpose | Service Tag|
23
+
| Address | Outbound TCP port | Purpose | Service tag|
24
24
|---|---|---|---|
25
+
|`login.microsoftonline.com`| 443 | Authentication to Microsoft Online Services |
25
26
|`*.wvd.microsoft.com`| 443 | Service traffic | WindowsVirtualDesktop |
> We have finished transitioning the URLs we use for Agent traffic. We no longer support the URLs below. To avoid your session host VMs from showing *Needs Assistance*related to this, please allow `*.prod.warm.ingest.monitor.core.windows.net` if you have not already. Please remove these URLs if you have previously explicitly allowed them:
40
+
> We've finished transitioning the URLs we use for Agent traffic. We no longer support the following URLs. To prevent your session host VMs from showing a *Needs Assistance*status, You must allow `*.prod.warm.ingest.monitor.core.windows.net` if you haven't already. You must also remove the following URLs if you explicitly allowed them before the change:
40
41
>
41
-
> | Address | Outbound TCP port | Purpose | Service Tag|
42
+
> | Address | Outbound TCP port | Purpose | Service tag|
|`wvdportalstorageblob.blob.core.usgovcloudapi.net`| 443 | Azure portal support | AzureCloud |
73
74
|`169.254.169.254`| 80 |[Azure Instance Metadata service endpoint](../virtual-machines/windows/instance-metadata-service.md)| N/A |
74
75
|`168.63.129.16`| 80 |[Session host health monitoring](../virtual-network/network-security-groups-overview.md#azure-platform-considerations)| N/A |
75
76
|`ocsp.msocsp.com`| 80 | Certificates | N/A |
76
77
77
78
> [!IMPORTANT]
78
-
> We have finished transitioning the URLs we use for Agent traffic. We no longer support the URLs below. To avoid your session host VMs from showing *Needs Assistance*related to this, please allow `*.prod.warm.ingest.monitor.core.usgovcloudapi.net`, if you have not already. Please remove these URLs if you have previously explicitly allowed them:
79
+
> We've finished transitioning the URLs we use for Agent traffic. We no longer support the following URLs. To prevent your session host VMs from showing a *Needs Assistance*status, you must allow the URL `*.prod.warm.ingest.monitor.core.usgovcloudapi.net`, if you haven't already. You must also remove the following URLs if you explicitly allowed them before the change:
79
80
>
80
-
> | Address | Outbound TCP port | Purpose | Service Tag|
81
+
> | Address | Outbound TCP port | Purpose | Service tag|
@@ -89,7 +90,6 @@ The following table lists optional URLs that your session host virtual machines
89
90
90
91
| Address | Outbound TCP port | Purpose |
91
92
|--|--|--|
92
-
|`login.microsoftonline.us`| 443 | Authentication to Microsoft Online Services and Microsoft 365 |
93
93
|`*.events.data.microsoft.com`| 443 | Telemetry Service |
94
94
|`www.msftconnecttest.com`| 443 | Detects if the OS is connected to the internet |
95
95
|`*.prod.do.dsp.mp.microsoft.com`| 443 | Windows Update |
@@ -121,7 +121,7 @@ Azure Virtual Desktop currently doesn't have a list of IP address ranges that yo
121
121
122
122
## Remote Desktop clients
123
123
124
-
Any [Remote Desktop clients](user-documentation/connect-windows-7-10.md?toc=%2Fazure%2Fvirtual-desktop%2Ftoc.json&bc=%2Fazure%2Fvirtual-desktop%2Fbreadcrumb%2Ftoc.json) you use to connect to Azure Virtual Desktop must have access to the URLs below. Select the relevant tab based on which cloud you're using. Opening these URLs is essential for a reliable client experience. Blocking access to these URLs is unsupported and will affect service functionality.
124
+
Any [Remote Desktop clients](user-documentation/connect-windows-7-10.md?toc=%2Fazure%2Fvirtual-desktop%2Ftoc.json&bc=%2Fazure%2Fvirtual-desktop%2Fbreadcrumb%2Ftoc.json) you use to connect to Azure Virtual Desktop must have access to the following URLs. Select the relevant tab based on which cloud you're using. Opening these URLs is essential for a reliable client experience. Blocking access to these URLs is unsupported and will affect service functionality.
125
125
126
126
# [Azure cloud](#tab/azure)
127
127
@@ -150,3 +150,7 @@ Any [Remote Desktop clients](user-documentation/connect-windows-7-10.md?toc=%2Fa
150
150
---
151
151
152
152
These URLs only correspond to client sites and resources. This list doesn't include URLs for other services like Azure Active Directory or Office 365. Azure Active Directory URLs can be found under IDs 56, 59 and 125 in [Office 365 URLs and IP address ranges](/office365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online).
153
+
154
+
## Next steps
155
+
156
+
To learn how to unblock these URLs in Azure Firewall for your Azure Virtual Desktop deployment, see [Use Azure Firewall to protect Azure Virtual Desktop](../firewall/protect-azure-virtual-desktop.md).
0 commit comments