Clarification on upcoming Intune network changes and AFD endpoints

InfraSolutions 811 Reputation points
2026-03-06T11:23:33.0466667+00:00

Hello,

I am reviewing a Microsoft Intune Customer Success blog post about upcoming Intune network changes where Intune traffic may start routing through Azure Front Door. The article recommends adding new service endpoints in addition to the existing Intune endpoints.

I would appreciate some clarification.

The article mentions the rollout may start on or shortly after December 2025, but it is not clear when organizations should complete adding these endpoints.

What could be the impact if these new endpoints are not added to firewall or proxy allow lists? At the moment we are not experiencing any issues.

Also, will this change apply to all Intune device communication, or only to certain features?

Our organization relies heavily on Windows Autopilot and mobile device management for device enrollment and policy deployment, so I would like to understand if these scenarios could be affected.

Any guidance or best practices would be greatly appreciated.

Thank you.

Microsoft Security | Intune | Configuration

1 answer

Sort by: Newest
  1. AI answer

    2026-03-06T11:23:52.6533333+00:00

    Completion timeline:

    • Intune began using Azure Front Door (AFD) IP addresses in addition to existing Intune service IPs starting in December 2025 as part of the Secure Future Initiative.
    • Guidance is to have firewall rules updated by December 2, 2025, to include the new AFD ranges or the AzureFrontDoor.MicrosoftSecurity service tag.

    Impact if new endpoints are not added:

    If outbound traffic is restricted by IP or service tag and the new AFD ranges are not allowed, devices can experience:

    • Sign-in issues for users.
    • Loss of device connectivity with Intune.
    • Disruption accessing the Intune Company Portal and apps protected by app protection policies.
    • Degraded or failed device connectivity that affects core Intune functions, including device and app management.

    Organizations that:

    • Use FQDN-based rules (for example, wildcard *.manage.microsoft.com) or
    • Do not restrict outbound traffic

    typically do not need changes, but should verify that wildcard FQDN rules are in place so all Intune services remain reachable.

    Scope of the change (what traffic is affected):

    • Intune endpoints use Azure Front Door for communicating with the Intune service.
    • Intune-specific endpoints are referenced in the Azure IP ranges JSON by the name AzureFrontDoor.MicrosoftSecurity.
    • For Intune client and host service, the required AFD IP ranges (commercial) include:
      • 13.107.219.0/24
      • 13.107.227.0/24
      • 13.107.228.0/23
      • 150.171.97.0/24
      • 2620:1ec:40::/48
      • 2620:1ec:49::/48
      • 2620:1ec:4a::/47
    • For US government endpoints, additional AFD ranges are required:
      • 51.54.53.136/29
      • 51.54.114.160/29
      • 62.11.173.176/29

    This change applies to Intune service communication generally, not just a single feature. It is specifically called out as affecting customers that:

    • Use IP-based allowlists, Azure service tags, or
    • Have strict outbound filtering in firewalls, VPNs, proxies, or other network infrastructure.

    Potential impact on Windows Autopilot and MDM scenarios:

    • The change is described as affecting “core Intune functions including device and app management.”
    • If managed devices cannot reach the updated Intune endpoints over AFD, scenarios such as:
      • Device enrollment
      • Policy deployment
      • App deployment and updates
      • Ongoing device management

    can be degraded or fail. This includes Windows Autopilot and mobile device management enrollment and policy flows, because they rely on Intune service connectivity.

    Network requirements for scripts and Win32 apps (related traffic):

    • For PowerShell scripts and Win32 apps, Intune uses regional CDNs and AFD-based endpoints such as:
      • North America: naprodimedatapri.azureedge.net, naprodimedatasec.azureedge.net, naprodimedatahotfix.azureedge.net, imeswda-afd-primary.manage.microsoft.com, imeswda-afd-secondary.manage.microsoft.com, imeswda-afd-hotfix.manage.microsoft.com
      • Europe: euprodimedatapri.azureedge.net, euprodimedatasec.azureedge.net, euprodimedatahotfix.azureedge.net, imeswdb-afd-primary.manage.microsoft.com, imeswdb-afd-secondary.manage.microsoft.com, imeswdb-afd-hotfix.manage.microsoft.com
      • Asia Pacific: approdimedatapri.azureedge.net, approdimedatasec.azureedge.net, approdimedatahotfix.azureedge.net, imeswdc-afd-primary.manage.microsoft.com, imeswdc-afd-secondary.manage.microsoft.com, imeswdc-afd-hotfix.manage.microsoft.com
    • These require outbound TCP 443. Starting March 2025, the azureedge.net domains migrate to manage.microsoft.com.

    Best practices and guidance:

    1. Prefer FQDN-based allow rules
      • Use wildcard FQDN rules such as *.manage.microsoft.com wherever possible. This reduces administrative overhead and automatically covers new AFD-backed endpoints.
    2. If IP-based allowlists are required
      • Add the AFD IP ranges listed above or use the AzureFrontDoor.MicrosoftSecurity service tag in firewall, proxy, and VPN rules.
      • Do not remove any existing Intune network endpoints; the AFD ranges are in addition to current Intune IPs.
    3. Validate before issues appear
      • Even if there are no issues today, update rules proactively so that when traffic shifts to AFD, device connectivity and enrollment flows (including Windows Autopilot and MDM) are not impacted.
    4. Use official endpoint lists
      • For the authoritative and up-to-date list of endpoints for Intune client and host services, use the Intune core service section in Network endpoints for Microsoft Intune.
      • For US government tenants, use the Ports and IP addresses list in US government endpoints for Microsoft Intune.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.