Intune Network / Ports requirements
Below are the Networking requirements for Autopilot as recommended by Microsoft.
- After a network connection is in place, each Windows 10 device will contact the Windows Autopilot Deployment Service. With Windows 10 version 1903 and above, the following URLs are used:
https://ztd.dds.microsoft.com,
https://cs.dds.microsoft.com, and
|
Allow access to all hosts via port 80 (HTTP), 443 (HTTPS), and 123 (UDP/NTP) |
- Once authenticated, Azure Active Directory will trigger enrollment of the device into the Intune mobile device management (MDM) service. See the following link for details about network communication requirements:
- Configure the proxy server to exclude the URLs for the certificate revocation lists (CRLs) from the requirements for Basic authentication. To do this, configure the following list of CRLs to be unauthenticated on the proxy server:
https://activation.sls.microsoft.com/
http://crl.microsoft.com/pki/crl/products/MicProSecSerCA_2007-12-04.crl
https://validation.sls.microsoft.com/
https://activation-v2.sls.microsoft.com/
https://validation-v2.sls.microsoft.com/
https://displaycatalog.mp.microsoft.com/
https://licensing.mp.microsoft.com/
https://purchase.mp.microsoft.com/
https://displaycatalog.md.mp.microsoft.com/
https://licensing.md.mp.microsoft.com/
https://purchase.md.mp.microsoft.com/
The following tables list the ports and services that the Intune client accesses:
Domains |
IP address |
---|---|
login.microsoftonline.com |
|
portal.manage.microsoft.com |
52.175.12.209 |
sts.manage.microsoft.com |
13.93.223.241 |
Manage.microsoft.com |
40.83.123.72 |
portal.fei.msua01.manage.microsoft.com |
52.160.70.20 |
portal.fei.msub01.manage.microsoft.com |
52.138.193.149 |
portal.fei.msuc01.manage.microsoft.com |
52.175.12.209 |
portal.fei.amsud0101.manage.microsoft.com |
13.72.226.202 |
fef.msua02.manage.microsoft.com |
52.177.194.236 |
fef.msua04.manage.microsoft.com |
23.96.112.28 |
fef.msua06.manage.microsoft.com |
13.78.185.97 |
fef.msuc03.manage.microsoft.com |
23.101.0.100 |
fef.amsua0502.manage.microsoft.com |
13.85.68.142 |
Admin.manage.microsoft.com |
52.224.221.227 |
wip.mam.manage.microsoft.com |
52.187.76.84 |
mam.manage.microsoft.com |
104.40.69.125 |
*.manage.microsoft.com |
40.82.248.224/28 |
- Check that your device can access these Windows Update endpoints:
http://windowsupdate.microsoft.com
http://*.windowsupdate.microsoft.com
https://*.windowsupdate.microsoft.com
https://*.update.microsoft.com
http://download.windowsupdate.com
https://download.microsoft.com
http://*.download.windowsupdate.com
http://ntservicepack.microsoft.com
https://*.prod.do.dsp.mp.microsoft.com
http://*.dl.delivery.mp.microsoft.com
https://*.delivery.mp.microsoft.com
https://tsfe.trafficshaping.dsp.mp.microsoft.com
- When a Windows device starts up, it will talk to a network time server to ensure that the time on the device is correct. Ensure that UDP port 123 to time.windows.com is accessible.
- Windows must be able to tell that the device can access the internet.
www.msftconnecttest.com must be resolvable via DNS and accessible via HTTP.