require
*.officeapps.live.com, *.online.office.com, office.live.com
13.107.6.171/32, 13.107.18.15/32, 13.107.140.6/32, 52.108.0.0/14, 52.244.37.168/32, 2603:1006:1400::/40, 2603:1016:2400::/40, 2603:1026:2400::/40, 2603:1036:2400::/40, 2603:1046:1400::/40, 2603:1056:1400::/40, 2603:1063:2000::/38, 2620:1ec:c::15/128, 2620:1ec:8fc::6/128, 2620:1ec:a92::171/128, 2a01:111:f100:2000::a83e:3019/128, 2a01:111:f100:2002::8975:2d79/128, 2a01:111:f100:2002::8975:2da8/128, 2a01:111:f100:7000::6fdd:6cd5/128, 2a01:111:f100:a004::bfeb:88cf/128
require
*.office.net
UDP: 443
require
* .onenote.com
optional
note : OneNote notebook ( wildcard )
*.microsoft.com
require
*cdn.onenote.net
require
ajax.aspnetcdn.com, apis.live.net, officeapps.live.com, www.onedrive.com
require
*.auth.microsoft.com, *.msftidentity.com, *.msidentity.com, account.activedirectory.windowsazure.com, accounts.accesscontrol.windows.net, adminwebservice.microsoftonline.com, api.passwordreset.microsoftonline.com, autologon.microsoftazuread-sso.com, becws.microsoftonline.com, ccs.login.microsoftonline.com, clientconfig.microsoftonline-p.net, companymanager.microsoftonline.com, device.login.microsoftonline.com, graph.microsoft.com, graph.windows.net, login-us.microsoftonline.com, login.microsoft.com, login.microsoftonline-p.com, login.microsoftonline.com, login.windows.net, logincert.microsoftonline.com, loginex.microsoftonline.com, nexus.microsoftonline-p.com, passwordreset.microsoftonline.com, provisioningapi.microsoftonline.com
20.20.32.0/19 , 20.190.128.0/18 , 20.231.128.0/19 , 40.126.0.0/18 , 2603:1006:2000::/48 , 2603:1007:200::/48 , 2603:1016:1400::/48 , 2603:1017::/48 , 2603:1026:3000::/48 , 2603:1027:1::/48 , 2603:1036:3000::/48 , 2603:1037:1::/48 , 2603:1046:2000::/48 , 2603:1047:1::/48 , 2603:1056:2000::/48 , 2603:1057:2::/48
require
*.hip.live.com, *.microsoftonline-p.com, *.microsoftonline.com, *.msauth.net, *.msauthimages.net, *.msecnd.net, *.msftauth.net, *.msftauthimages.net, *.phonefactor.net, enterpriseregistration.windows.net, policykeyservice.dc.ad.msft.net
require
*.protection.office.com, *.security.microsoft.com, compliance.microsoft.com, defender.microsoft.com, protection.office.com, purview.microsoft.com, security.microsoft.com
13.107.6.192/32, 13.107.9.192/32, 2620:1ec:4::192/128, 2620:1ec:a92::192/128
require
* .portal.cloudappsecurity.com
optional
Notes: Portal and shared: 3rd party office integration. (including CDNs)
firstpartyapps.oaspapps.com , prod.firstpartyapps.oaspapps.com.akadns.net , telemetryservice.firstpartyapps.oaspapps.com , wus-firstpartyapps.oaspapps.com
require
*.aria.microsoft.com, *.events.data.microsoft.com
require
* .o365weve.com , amp.azure.net , appsforoffice.microsoft.com , assets.onestore.ms , auth.gfx.ms , c1.microsoft.com , dgps.support.microsoft.com , docs.microsoft.com , msdn.microsoft.com , platform.linkedin.com , prod.msocdn.com , shellprod.msocdn.com , support.microsoft.com , technet.microsoft.com
require
*.office365.com
require
*.aadrm.com, *.azurerms.com, *.informationprotection.azure.com, ecn.dev.virtualearth.net, informationprotection.hosting.portal.azure.net
optional
Notes: Graph.windows.net, Office 365 Management Pack for Operations Manager, SecureScore, Azure AD Device Registration, Forms, StaffHub, Application Insights, captcha services
*.sharepointonline.com, dc.services.visualstudio.com, mem.gfx.ms, staffhub.ms, staffhubweb.azureedge.net
optional
Notes: Some Office 365 features require endpoints within these domains (including CDNs). Many specific FQDNs within these wildcards have been published recently as we work to either remove or better explain our guidance relating to these wildcards.
*.microsoft.com, *.msocdn.com, *.onmicrosoft.com
require
o15.officeredir.microsoft.com, officepreviewredir.microsoft.com, officeredir.microsoft.com, r.office.microsoft.com
require
activation.sls.microsoft.com
require
crl.microsoft.com
require
office15client.microsoft.com, officeclient.microsoft.com
require
go.microsoft.com
require
ajax.aspnetcdn.com, cdn.odc.officeapps.live.com
require
officecdn.microsoft.com, officecdn.microsoft.com.edgesuite.net, otelrules.azureedge.net
optional
note : ProPlus : auxiliary url
* .virtualearth.net , c.bing.net , ocos-office365-s2s.msedge.net , tse1.mm.bing.net , www.bing.com
optional
note : outlook for Android and ios
*.acompli.net, *.outlookmobile.com
optional
note : outlook for Android and ios: Authentication
login.windows-ppe.net
optional
note : outlook for Android and ios: Consumer Outlook.com and OneDrive integration
account.live.com, login.live.com
optional
note : outlook for Android and ios: Outlook Privacy
www.acompli.com
optional
Notes: Office Mobile URLs
*.appex-rf.msn.com, *.appex.bing.com, c.bing.com, c.live.com, d.docs.live.net, docs.live.net, partnerservices.getmicrosoftkey.com, signup.live.com
optional
Notes: Office for iPad URLs
account.live.com, auth.gfx.ms, login.live.com
optional
Notes: Yammer
*.yammer.com, *.yammerusercontent.com
optional
Notes: Yammer CDN
* .assets - yammer.com
optional
Notes: Planner: auxiliary URLs
www.outlook.com
optional
note : sway CDNs
eus-www.sway-cdn.com, eus-www.sway-extensions.com, wus-www.sway-cdn.com, wus-www.sway-extensions.com
optional
note : sway
sway.com, www.sway.com
require
*.entrust.net, *.geotrust.com, *.omniroot.com, *.public-trust.com, *.symcb.com, *.symcd.com, *.verisign.com, *.verisign.net, apps.identrust.com, cacerts.digicert.com, cert.int-x3.letsencrypt.org, crl.globalsign.com, crl.globalsign.net, crl.identrust.com, crl3.digicert.com, crl4.digicert.com, isrg.trustid.ocsp.identrust.com, mscrl.microsoft.com, ocsp.digicert.com, ocsp.globalsign.com, ocsp.msocsp.com, ocsp2.globalsign.com, ocspx.digicert.com, secure.globalsign.com, www.digicert.com, www.microsoft.com
optional
Notes: Connection to the speech service is required for Office Dictation features. If connectivity is not allowed, Dictation will be disabled.
officespeech.platform.bing.com
require
*.office.com, www.microsoft365.com
optional
note : These endpoint enable the Office Scripts functionality in office client available through the Automate tab and the Python in Excel functionality available through the Formulas tab . The Office Scripts feature can also be disabled through the Office 365 Admin portal . For admin control relate to Python in Excel , see Data security and Python in Excel .
*.microsoftusercontent.com
require
*.azure-apim.net, *.flow.microsoft.com, *.powerapps.com, *.powerautomate.com
require
*.activity.windows.com, activity.windows.com
require
*.cortana.ai
require
admin.microsoft.com
require
cdn.odc.officeapps.live.com , cdn.uci.officeapps.live.com
require
*.cloud.microsoft, *.static.microsoft, *.usercontent.microsoft
UDP: 443
© Copyright notes
The copyright of the article belongs to the author, please do not reprint without permission.
Related posts
No comments...