Static IP address for login.microsoftonline.com

Sruthi Kudaravalli 1 Reputation point
2021-11-04T23:38:26.687+00:00

Is there a static IP address for login.microsoftonline.com. Our tools are using Azure Active Directory to authenticate users and our customers have firewall to filter unwanted traffic. I don't see a static IP address for login.microsoftonline.com to allow it through the firewall.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,457 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Stuart Eggerton 6 Reputation points Microsoft Employee
    2021-11-04T23:50:14.183+00:00

    login.microsoftonline.com is a globally distributed service with multiple IP addresses. If it is possible I would suggest outbound proxy filtering by hostname (FQDN) instead of IP for such endpoints or else you end up with a huge maintenance overhead if a vendor e.g. Microsoft change the IP address.

    If you are using Azure Firewall then this is the feature https://learn.microsoft.com/en-us/azure/firewall/fqdn-filtering-network-rules

    Similar features exist with Fortigate etc..

    1 person found this answer helpful.
    0 comments No comments