Update firewall configurations to include new Intune network endpoints

 This morning, I noticed this notification in Microsoft Intune started showing.

 

A screenshot of a computer

AI-generated content may be incorrect.

 

If you click on the link, it will take you to M365 Admin Center,

A screenshot of a computer

AI-generated content may be incorrect.

I reviewed the document to ensure I understand everything before I apply it.

So, what to do?

According to Microsoft Document, there are changes in IP Ranges and Service Tags for both Public and Government Cloud. These changes are part of the Secure Feature Initiative (SFI) and must be completed before December 2nd, 2025.

Entities (companies and government) need to configure their outbound firewall traffic for Intune or Azure to match Microsoft's new ranges. This must be done on the firewall, router, proxy, and NSG levels, also by adding the new ranges without removing any existing network or firewall configuration. Include a new Azure Front Door tag, ‘AzureFrontDoor.MicrosoftSecurity’. To download the document (JSON) file for the government and the public, click the links below.

If you search you should find these ranges:

A screenshot of a computer code

AI-generated content may be incorrect.

This change is needed for both MDM and MAM. If these changes in the network do not happen, the end user may have issues with device communication with Intune and applications in the cloud, policies, etc.

 

All resources are here:-

Comments

Popular posts from this blog

New LAPS for Windows 11 24H2

Windows Autopatch Hotpatch

How to block TikTok or other social media