Setting up and managing device configurations using Intune
Completion timeline:
- Intune began using Azure Front Door (AFD) IP addresses in addition to existing Intune service IPs starting in December 2025 as part of the Secure Future Initiative.
- Guidance is to have firewall rules updated by December 2, 2025, to include the new AFD ranges or the
AzureFrontDoor.MicrosoftSecurityservice tag.
Impact if new endpoints are not added:
If outbound traffic is restricted by IP or service tag and the new AFD ranges are not allowed, devices can experience:
- Sign-in issues for users.
- Loss of device connectivity with Intune.
- Disruption accessing the Intune Company Portal and apps protected by app protection policies.
- Degraded or failed device connectivity that affects core Intune functions, including device and app management.
Organizations that:
- Use FQDN-based rules (for example, wildcard
*.manage.microsoft.com) or - Do not restrict outbound traffic
typically do not need changes, but should verify that wildcard FQDN rules are in place so all Intune services remain reachable.
Scope of the change (what traffic is affected):
- Intune endpoints use Azure Front Door for communicating with the Intune service.
- Intune-specific endpoints are referenced in the Azure IP ranges JSON by the name
AzureFrontDoor.MicrosoftSecurity. - For Intune client and host service, the required AFD IP ranges (commercial) include:
- 13.107.219.0/24
- 13.107.227.0/24
- 13.107.228.0/23
- 150.171.97.0/24
- 2620:1ec:40::/48
- 2620:1ec:49::/48
- 2620:1ec:4a::/47
- For US government endpoints, additional AFD ranges are required:
- 51.54.53.136/29
- 51.54.114.160/29
- 62.11.173.176/29
This change applies to Intune service communication generally, not just a single feature. It is specifically called out as affecting customers that:
- Use IP-based allowlists, Azure service tags, or
- Have strict outbound filtering in firewalls, VPNs, proxies, or other network infrastructure.
Potential impact on Windows Autopilot and MDM scenarios:
- The change is described as affecting “core Intune functions including device and app management.”
- If managed devices cannot reach the updated Intune endpoints over AFD, scenarios such as:
- Device enrollment
- Policy deployment
- App deployment and updates
- Ongoing device management
can be degraded or fail. This includes Windows Autopilot and mobile device management enrollment and policy flows, because they rely on Intune service connectivity.
Network requirements for scripts and Win32 apps (related traffic):
- For PowerShell scripts and Win32 apps, Intune uses regional CDNs and AFD-based endpoints such as:
- North America:
naprodimedatapri.azureedge.net,naprodimedatasec.azureedge.net,naprodimedatahotfix.azureedge.net,imeswda-afd-primary.manage.microsoft.com,imeswda-afd-secondary.manage.microsoft.com,imeswda-afd-hotfix.manage.microsoft.com - Europe:
euprodimedatapri.azureedge.net,euprodimedatasec.azureedge.net,euprodimedatahotfix.azureedge.net,imeswdb-afd-primary.manage.microsoft.com,imeswdb-afd-secondary.manage.microsoft.com,imeswdb-afd-hotfix.manage.microsoft.com - Asia Pacific:
approdimedatapri.azureedge.net,approdimedatasec.azureedge.net,approdimedatahotfix.azureedge.net,imeswdc-afd-primary.manage.microsoft.com,imeswdc-afd-secondary.manage.microsoft.com,imeswdc-afd-hotfix.manage.microsoft.com
- North America:
- These require outbound TCP 443. Starting March 2025, the
azureedge.netdomains migrate tomanage.microsoft.com.
Best practices and guidance:
- Prefer FQDN-based allow rules
- Use wildcard FQDN rules such as
*.manage.microsoft.comwherever possible. This reduces administrative overhead and automatically covers new AFD-backed endpoints.
- Use wildcard FQDN rules such as
- If IP-based allowlists are required
- Add the AFD IP ranges listed above or use the
AzureFrontDoor.MicrosoftSecurityservice tag in firewall, proxy, and VPN rules. - Do not remove any existing Intune network endpoints; the AFD ranges are in addition to current Intune IPs.
- Add the AFD IP ranges listed above or use the
- Validate before issues appear
- Even if there are no issues today, update rules proactively so that when traffic shifts to AFD, device connectivity and enrollment flows (including Windows Autopilot and MDM) are not impacted.
- Use official endpoint lists
- For the authoritative and up-to-date list of endpoints for Intune client and host services, use the Intune core service section in Network endpoints for Microsoft Intune.
- For US government tenants, use the Ports and IP addresses list in US government endpoints for Microsoft Intune.
References: