Hi Favour Adesiyan,
Thanks for reaching out to Microsoft!
As per the Microsoft documentation, you can configure the firewall that protects your endpoint to allow inbound connections only from Microsoft Graph, reducing further exposure to invalid change notifications.
Note: The listed IP addresses that are used to deliver change notifications can be updated at any time without notice.
Hope this helps.
If the answer is helpful, please click Accept Answer and kindly upvote. If you have any further questions about this answer, please click Comment.