Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1150664

Action Required: Update firewall configurations to include new network endpoints

Plan for Change

Message ID

MC1150664
View in Admin Center

Services

Basic Mobility and Security

Summary

By December 2, 2025, update firewall allowlists to include Azure Front Door IP addresses or the service tag "AzureFrontDoor.MicrosoftSecurity" for Microsoft Intune and Basic Mobility and Security for Microsoft 365. Do not remove existing endpoints; add new ranges from the provided Azure IP range files.

Details

As part of Microsoft’s ongoing Secure Future Initiative (SFI), starting on or shortly after December 2, 2025, the network service endpoints for Microsoft Intune will also use the Azure Front Door IP addresses. Since Basic Mobility and Security for Microsoft 365 uses Intune infrastructure, customers may need to add Azure Front Door IP addresses, if using a firewall allowlist that allows outbound traffic based on IP addresses or Azure service tags.

Do not remove any existing network endpoints required for Basic Mobility and Security for Microsoft 365. Additional network endpoints are documented as part of the Azure Front Door and service tags information referenced in the files linked below:

  • Public clouds: Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center 
  • Government clouds: Download Azure IP Ranges and Service Tags – US Government Cloud from Official Microsoft Download Center 

The additional ranges are those listed in the JSON files linked above and can be found by searching for “AzureFrontDoor.MicrosoftSecurity”.

How this will affect your organization:

If you have configured an outbound traffic policy for IP address ranges or Azure service tags for your firewalls, routers, proxy servers, client-based firewalls, VPN or network security groups, you will need to update them to include the new Azure Front Door ranges with the “AzureFrontDoor.MicrosoftSecurity” tag. 

What you need to do to prepare:

Ensure that your firewall rules are updated and added to your firewall’s allowlist with the additional IP addresses documented under Azure Front Door by December 2, 2025. 

Alternatively, you may add the service tag “AzureFrontDoor.MicrosoftSecurity” to your firewall rules to allow outbound traffic on port 443 for the addresses in the tag. 

If you are not the IT admin who can make this change, notify your networking team. If you are responsible for configuring internet traffic, refer to the following documentation for more details:

  • Azure Front Door
  • Azure service tags

If you have a helpdesk, inform them about this upcoming change. If you need additional assistance, contact Microsoft Support and refer to this message center post.

Timeline

Published
Sep 9, 2025
Message published to Message Center
Updated
Sep 9, 2025
Message content updated
Action Required By
Dec 1, 2025
Action deadline
End Date
Mar 31, 2026
Message timeline ends

Tags

#User impact#Admin impact

Category

Plan for Change

Related Messages

Similar updates

MC1183282

Reminder: Update firewall configurations to include new network endpoints

Nov 6, 2025
MC1141958

Microsoft Teams: Choose to hide inactive channels

Aug 25, 2025
MC1143276

Microsoft Viva Engage: Smarter delivery of Community Announcement notifications

Aug 27, 2025
MC1158908â—Ź

(Update)Support for Events from email in Outlook is changing—Schema.org markup required for reliable calendar extraction

Sep 24, 2025
MC1152323â—Ź

Microsoft 365 Copilot Apps installation on devices with Microsoft 365 Apps

Sep 12, 2025