Microsoft 365 requires connectivity to the Internet. The endpoints in this article should be reachable for customers using Microsoft 365 plans, including Government Community Cloud (GCC).
Microsoft 365 Worldwide (+GCC) | Microsoft 365 operated by 21 Vianet | Microsoft 365 U.S. Government DoD | Microsoft 365 U.S. Government GCC High |
Start with Managing Microsoft 365 endpoints to understand our recommendations for managing network connectivity using this data. Endpoints data is updated as needed at the beginning of each month with new IP Addresses and URLs published 30 days in advance of being active. This cadence allows for customers who don't yet have automated updates to complete their processes before new connectivity is required. Endpoints may also be updated during the month if needed to address support escalations, security incidents, or other immediate operational requirements. The data shown on this page below is all generated from the REST-based web services. If you're using a script or a network device to access this data, you should go to the Web service directly.
Endpoint data below lists requirements for connectivity from a user's machine to Microsoft 365. For detail on IP addresses used for network connections from Microsoft into a customer network, sometimes called hybrid or inbound network connections, see other endpoints for more information.
The endpoints are grouped into four service areas representing the three primary workloads and a set of common resources. The groups may be used to associate traffic flows with a particular application, however given that features often consume endpoints across multiple workloads, these groups can't effectively be used to restrict access.
Data columns shown are:
ID: The ID number of the row, also known as an endpoint set. This ID is the same as is returned by the web service for the endpoint set.
Category: Shows whether the endpoint set is categorized as Optimize, Allow, or Default. This column also lists which endpoint sets are required to have network connectivity. For endpoint sets that aren't required to have network connectivity, we provide notes in this field to indicate what functionality would be missing if the endpoint set is blocked.
You can read about these categories and guidance for their management in Optimizing connectivity to Microsoft 365 services.
ER: This is Yes if the endpoint set is supported over Azure ExpressRoute with Microsoft 365 route prefixes. The BGP community that includes the route prefixes shown aligns with the service area listed. When ER is No, this means that ExpressRoute isn't supported for this endpoint set.
Some routes may be advertised in more than one BGP community, making it possible for endpoints within a given IP range to traverse the ER circuit, but still be unsupported. In all cases, the value of a given endpoint set's ER column should be respected.
Addresses: Lists the FQDNs or wildcard domain names and IP address ranges for the endpoint set. Note that an IP address range is in CIDR format and may include many individual IP addresses in the specified network.
Ports: Lists the TCP or UDP ports that are combined with listed IP addresses to form the network endpoint. You may notice some duplication in IP address ranges where there are different ports listed.
Note
In response to customer feedback and to streamline endpoint management, Microsoft has initiated the process of consolidating Microsoft 365 apps and services into a select group of dedicated, secured, and purpose-managed domains within the .microsoft top level domain (TLD).
To avoid connectivity issues for users, ensure that the following essential domains are included in your allowlist and that connectivity to these domains isn't blocked.
ID Category Domain name Purpose Ports 184 Required*.cloud.microsoft
Dedicated to authenticated user facing Microsoft SaaS product experiences. TCP: 443
*.static.microsoft
Dedicated to static (not customer generated) content hosted on CDNs. TCP: 443
*.usercontent.microsoft
Content used in Microsoft 365 experiences that requires domain isolation from applications. TCP: 443
outlook.cloud.microsoft, outlook.office.com, outlook.office365.com
13.107.6.152/31, 13.107.18.10/31, 13.107.128.0/22, 23.103.160.0/20, 40.96.0.0/13, 40.104.0.0/15, 52.96.0.0/14, 131.253.33.215/32, 132.245.0.0/16, 150.171.32.0/22, 204.79.197.215/32, 2603:1006::/40, 2603:1016::/36, 2603:1026::/36, 2603:1036::/36, 2603:1046::/36, 2603:1056::/36, 2620:1ec:4::152/128, 2620:1ec:4::153/128, 2620:1ec:c::10/128, 2620:1ec:c::11/128, 2620:1ec:d::10/128, 2620:1ec:d::11/128, 2620:1ec:8f0::/46, 2620:1ec:900::/46, 2620:1ec:a92::152/128, 2620:1ec:a92::153/128
TCP: 443, 80
outlook.office365.com, smtp.office365.com
13.107.6.152/31, 13.107.18.10/31, 13.107.128.0/22, 23.103.160.0/20, 40.96.0.0/13, 40.104.0.0/15, 52.96.0.0/14, 131.253.33.215/32, 132.245.0.0/16, 150.171.32.0/22, 204.79.197.215/32, 2603:1006::/40, 2603:1016::/36, 2603:1026::/36, 2603:1036::/36, 2603:1046::/36, 2603:1056::/36, 2620:1ec:4::152/128, 2620:1ec:4::153/128, 2620:1ec:c::10/128, 2620:1ec:c::11/128, 2620:1ec:d::10/128, 2620:1ec:d::11/128, 2620:1ec:8f0::/46, 2620:1ec:900::/46, 2620:1ec:a92::152/128, 2620:1ec:a92::153/128
TCP: 587, 993, 995, 143 8 Default
*.outlook.com, autodiscover.<tenant>.onmicrosoft.com
TCP: 443, 80 9 Allow
*.protection.outlook.com
40.92.0.0/15, 40.107.0.0/16, 52.100.0.0/14, 52.238.78.88/32, 104.47.0.0/17, 2a01:111:f400::/48, 2a01:111:f403::/48
TCP: 443 10 Allow
*.mail.protection.outlook.com, *.mx.microsoft
40.92.0.0/15, 40.107.0.0/16, 52.100.0.0/14, 104.47.0.0/17, 2a01:111:f400::/48, 2a01:111:f403::/48
TCP: 25 ID Category ER Addresses Ports 31 Optimize
*.sharepoint.com
13.107.136.0/22, 40.108.128.0/17, 52.104.0.0/14, 104.146.128.0/17, 150.171.40.0/22, 2603:1061:1300::/40, 2603:1063:6000::/35, 2620:1ec:8f8::/46, 2620:1ec:908::/46, 2a01:111:f402::/48
TCP: 443, 80
storage.live.com
TCP: 443 33 Default
*.search.production.apac.trafficmanager.net, *.search.production.emea.trafficmanager.net, *.search.production.us.trafficmanager.net
TCP: 443 35 Default
*.wns.windows.com, admin.onedrive.com, officeclient.microsoft.com
TCP: 443, 80 36 Default
g.live.com, oneclient.sfx.ms
TCP: 443, 80 37 Default
*.sharepointonline.com, spoprod-a.akamaihd.net
TCP: 443, 80 39 Default
*.svc.ms
TCP: 443, 80 Microsoft Teams ID Category ER Addresses Ports 11 Optimize
52.112.0.0/14, 52.122.0.0/15, 2603:1063::/38
UDP: 3478, 3479, 3480, 3481 12 Allow
*.lync.com, *.teams.cloud.microsoft, *.teams.microsoft.com, teams.cloud.microsoft, teams.microsoft.com
52.112.0.0/14, 52.122.0.0/15, 2603:1027::/48, 2603:1037::/48, 2603:1047::/48, 2603:1057::/48, 2603:1063::/38, 2620:1ec:6::/48, 2620:1ec:40::/42
TCP: 443, 80
*.keydelivery.mediaservices.windows.net, *.streaming.mediaservices.windows.net
TCP: 443 17 Default
aka.ms
TCP: 443 19 Default
adl.windows.com
TCP: 443, 80 27 Default
join.secure.skypeassets.com, mlccdnprod.azureedge.net
TCP: 443 127 Default
*.skype.com
TCP: 443, 80 180 Default
compass-ssl.microsoft.com
TCP: 443 Microsoft 365 Common and Office Online ID Category ER Addresses Ports 46 Allow
*.officeapps.live.com, *.online.office.com, office.live.com
13.107.6.171/32, 13.107.18.15/32, 13.107.140.6/32, 52.108.0.0/14, 52.244.37.168/32, 2603:1006:1400::/40, 2603:1016:2400::/40, 2603:1026:2400::/40, 2603:1036:2400::/40, 2603:1046:1400::/40, 2603:1056:1400::/40, 2603:1063:2000::/38, 2620:1ec:c::15/128, 2620:1ec:8fc::6/128, 2620:1ec:a92::171/128, 2a01:111:f100:2000::a83e:3019/128, 2a01:111:f100:2002::8975:2d79/128, 2a01:111:f100:2002::8975:2da8/128, 2a01:111:f100:7000::6fdd:6cd5/128, 2a01:111:f100:a004::bfeb:88cf/128
TCP: 443, 80 47 Default
*.office.net
TCP: 443, 80
*.onenote.com
TCP: 443 50 Default
*.microsoft.com
TCP: 443 51 Default
*cdn.onenote.net
TCP: 443 53 Default
ajax.aspnetcdn.com, apis.live.net, officeapps.live.com, www.onedrive.com
TCP: 443 56 Allow
*.auth.microsoft.com, *.msftidentity.com, *.msidentity.com, account.activedirectory.windowsazure.com, accounts.accesscontrol.windows.net, adminwebservice.microsoftonline.com, api.passwordreset.microsoftonline.com, autologon.microsoftazuread-sso.com, becws.microsoftonline.com, ccs.login.microsoftonline.com, clientconfig.microsoftonline-p.net, companymanager.microsoftonline.com, device.login.microsoftonline.com, graph.microsoft.com, graph.windows.net, login-us.microsoftonline.com, login.microsoft.com, login.microsoftonline-p.com, login.microsoftonline.com, login.windows.net, logincert.microsoftonline.com, loginex.microsoftonline.com, nexus.microsoftonline-p.com, passwordreset.microsoftonline.com, provisioningapi.microsoftonline.com
20.20.32.0/19, 20.190.128.0/18, 20.231.128.0/19, 40.126.0.0/18, 2603:1006:2000::/48, 2603:1007:200::/48, 2603:1016:1400::/48, 2603:1017::/48, 2603:1026:3000::/48, 2603:1027:1::/48, 2603:1036:3000::/48, 2603:1037:1::/48, 2603:1046:2000::/48, 2603:1047:1::/48, 2603:1056:2000::/48, 2603:1057:2::/48
TCP: 443, 80 59 Default
*.hip.live.com, *.microsoftonline-p.com, *.microsoftonline.com, *.msauth.net, *.msauthimages.net, *.msecnd.net, *.msftauth.net, *.msftauthimages.net, *.phonefactor.net, enterpriseregistration.windows.net
TCP: 443, 80 64 Allow
*.protection.office.com, *.security.microsoft.com, compliance.microsoft.com, defender.microsoft.com, protection.office.com, purview.microsoft.com, security.microsoft.com
13.107.6.192/32, 13.107.9.192/32, 2620:1ec:4::192/128, 2620:1ec:a92::192/128
TCP: 443 66 Default
*.portal.cloudappsecurity.com
TCP: 443 69 Default
*.aria.microsoft.com, *.events.data.microsoft.com
TCP: 443 70 Default
*.o365weve.com, amp.azure.net, appsforoffice.microsoft.com, assets.onestore.ms, auth.gfx.ms, c1.microsoft.com, dgps.support.microsoft.com, docs.microsoft.com, msdn.microsoft.com, platform.linkedin.com, prod.msocdn.com, shellprod.msocdn.com, support.microsoft.com, technet.microsoft.com
TCP: 443 71 Default
*.office365.com
TCP: 443, 80 73 Default
*.aadrm.com, *.azurerms.com, *.informationprotection.azure.com, ecn.dev.virtualearth.net, informationprotection.hosting.portal.azure.net
TCP: 443 75 Default
*.sharepointonline.com, dc.services.visualstudio.com, mem.gfx.ms
TCP: 443 78 Default
*.microsoft.com, *.msocdn.com, *.onmicrosoft.com
TCP: 443, 80 79 Default
o15.officeredir.microsoft.com, officepreviewredir.microsoft.com, officeredir.microsoft.com, r.office.microsoft.com
TCP: 443, 80 83 Default
activation.sls.microsoft.com
TCP: 443 84 Default
crl.microsoft.com
TCP: 443, 80 86 Default
office15client.microsoft.com, officeclient.microsoft.com
TCP: 443 89 Default
go.microsoft.com
TCP: 443, 80 91 Default
ajax.aspnetcdn.com, cdn.odc.officeapps.live.com
TCP: 443, 80 92 Default
officecdn.microsoft.com, officecdn.microsoft.com.edgesuite.net, otelrules.azureedge.net
TCP: 443, 80 93 Default
*.virtualearth.net, c.bing.net, ocos-office365-s2s.msedge.net, tse1.mm.bing.net, www.bing.com
TCP: 443, 80 95 Default
*.acompli.net, *.outlookmobile.com
TCP: 443 96 Default
login.windows-ppe.net
TCP: 443 97 Default
account.live.com, login.live.com
TCP: 443 105 Default
www.acompli.com
TCP: 443 114 Default
*.appex-rf.msn.com, *.appex.bing.com, c.bing.com, c.live.com, partnerservices.getmicrosoftkey.com, signup.live.com
TCP: 443, 80 116 Default
account.live.com, auth.gfx.ms, login.live.com
TCP: 443, 80 117 Default
<tenant>.yammer.com, <tenant>.yammerusercontent.com
TCP: 443 118 Default
*.assets-yammer.com
TCP: 443 121 Default
www.outlook.com
TCP: 443, 80 122 Default
eus-www.sway-cdn.com, eus-www.sway-extensions.com, wus-www.sway-cdn.com, wus-www.sway-extensions.com
TCP: 443 124 Default
sway.com, www.sway.com
TCP: 443 125 Default
*.entrust.net, *.geotrust.com, *.omniroot.com, *.public-trust.com, *.symcb.com, *.symcd.com, *.verisign.com, *.verisign.net, cacerts.digicert.com, cert.int-x3.letsencrypt.org, crl.globalsign.com, crl.globalsign.net, crl.identrust.com, crl3.digicert.com, crl4.digicert.com, isrg.trustid.ocsp.identrust.com, mscrl.microsoft.com, ocsp.digicert.com, ocsp.globalsign.com, ocsp.msocsp.com, ocsp2.globalsign.com, ocspx.digicert.com, oneocsp.microsoft.com, secure.globalsign.com, www.digicert.com, www.microsoft.com
TCP: 443, 80 126 Default
officespeech.platform.bing.com
TCP: 443 147 Default
*.office.com, www.microsoft365.com
TCP: 443, 80 152 Default
*.microsoftusercontent.com
TCP: 443 153 Default
*.azure-apim.net, *.flow.microsoft.com, *.powerapps.com, *.powerautomate.com
TCP: 443 156 Default
*.activity.windows.com, activity.windows.com
TCP: 443 158 Default
*.cortana.ai
TCP: 443 159 Default
admin.microsoft.com
TCP: 443, 80 160 Default
cdn.odc.officeapps.live.com, cdn.uci.officeapps.live.com
TCP: 443, 80 184 Default
*.cloud.microsoft, *.static.microsoft, *.usercontent.microsoft
TCP: 443
Notes for this table:
Other endpoints not included in the Microsoft 365 IP Address and URL Web service
Managing Microsoft 365 endpoints
General Microsoft Stream endpoints
Monitor Microsoft 365 connectivity
Microsoft Azure IP Ranges and Service Tags â Public Cloud
Microsoft Azure IP Ranges and Service Tags â US Government Cloud
Microsoft Azure IP Ranges and Service Tags â China Cloud
Service Name and Transport Protocol Port Number Registry
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4