Connect Health agent - Firewall rules (Outbound connectivity to the Azure service endpoints)

Dennis K 1 Reputation point
2021-10-21T05:39:36.79+00:00

I'm looking for some guidance on this article:
Azure AD Connect Health agent installation
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install

Down here:
https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-agent-install#outbound-connectivity-to-the-azure-service-endpoints
we aren't certain which ports must be opened for the first 4 "General public" endpoints:
*.blob.core.windows.net
*.aadconnecthealth.azure.com
*.servicebus.windows.net - Port: 5671 (This endpoint isn't required in the latest version of the agent.)
*.adhybridhealth.azure.com/

I'm not really concerned about #3, assuming I shouldn't have problems with the latest agent. But for 1,2, and 4, I don't know if opening port 443 on firewall would be sufficient.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. James Hamil 27,221 Reputation points Microsoft Employee Moderator
    2021-10-25T22:13:08.537+00:00

    Hi @Dennis K , following this document , port 443 looks to be the only port you need. Possibly 80 for servicebus.windows.net but it's not explicitly stated. I would stick with 443 unless you have any issues. Please let me know if you have any questions!

    If this answer helped you please mark it as "Verified" so other users may reference it.

    Thank you,
    James

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.