Share via

Function of 13.107.4.52

Anonymous
2022-12-30T07:50:24+00:00

Hi all, I have got report from our security operation center related to 13.107.4.52. The reputation say the IP is malicious and need to be blocked. But seem the operation is related to windows update in the scheduler. Can Microsoft confirm this IP is legit?.. so I can whitelist in our environment.

Windows for home | Other | Internet and connectivity

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

7 answers

Sort by: Most helpful
  1. Anonymous
    2023-01-29T12:46:01+00:00

    Zaid, this IP is legit and blocking it will cause workstations showing "No Internet".

    It's used by Network location awareness service , if you check registry Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet

    You will see ActiveWebProbeHost is pointed to www.msftconnecttest.com

    "nslookup -type=a www.msftconnecttest.com"  shows the DNS is resolved to13.107.4.52.

    Windows will do active http probe to http://www.msftconnecttest.com/connecttest.txt and expect to get "Microsoft Connect Test" content.

    If activeprobe failed, it will show the network connection as "No Internet", and it could cause problem for Outlook and OneDrive.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-12-30T08:49:55+00:00

    Yes, it has to be from Microsoft. But what is the purpose to connect by port 80.

    Was this answer helpful?

    0 comments No comments
  3. _AW_ 67,761 Reputation points Volunteer Moderator
    2022-12-30T08:36:27+00:00

    According to https://www.whois.com/whois/13.107.4.52 it's Microsoft.

    NetRange:       13.64.0.0 - 13.107.255.255
    CIDR:           13.104.0.0/14, 13.64.0.0/11, 13.96.0.0/13
    NetName:        MSFT
    NetHandle:      NET-13-64-0-0-1
    Parent:         NET13 (NET-13-0-0-0-0)
    NetType:        Direct Allocation
    OriginAS:       
    Organization:   Microsoft Corporation (MSFT)
    RegDate:        2015-03-26
    Updated:        2021-12-14
    Ref:            https://rdap.arin.net/registry/ip/13.64.0.0
    

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2022-12-30T08:34:32+00:00

    Yes online. Is there any other platform other that online I can check? I need to justify because the traffic is large more than 100k.

    Was this answer helpful?

    0 comments No comments
  5. Sumit D - IA 170.3K Reputation points Independent Advisor
    2022-12-30T08:22:05+00:00

    Hi Zaid,

    I am Sumit here to assist you with this question.

    We are independent experts that do not have this information, and Microsoft won't disclose the IP information as well if you contact support.

    Did you check IP reputation using tools on the Internet?

    Was this answer helpful?

    0 comments No comments