Azure Firewall Exceptions for O365 and Defender

Taranjeet Malik 446 Reputation points
2021-12-16T09:34:30.21+00:00

Hi

We have deployed Azure Firewall in a hub-spoke topology where the spoke is hosting Azure Virtual Desktop (AVD) session hosts.

I’ve gone through this this article for guidance on how to allow some of the basic Azure infra services (DNS, Health Monitoring, NTP, and KMS etc.)--> https://learn.microsoft.com/en-us/azure/firewall/protect-azure-virtual-desktop

However, it’s not clear on how to create rule exceptions for O365, MS Teams, and Defender. There’s a huge list of URLs and IP listed here for example--> https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-ip-web-service?view=o365-worldwide

Also, as the list changes often, would like to know how ppl. manage to keep the firewall rules up to date?

We’re seeing the following errors reported on virtual desktop sessions because of the missing rules / exceptions:

158211-defender-protection-updated-failed.gif

158212-ms-teams-connectivity-issue.gif

Thanks
Taranjeet Singh

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
581 questions
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
85 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. SaiKishor-MSFT 17,206 Reputation points
    2021-12-17T11:32:19.3+00:00

    @Taranjeet Malik Thank you for reaching out to Microsoft Q&a. I understand that you want to know how to create rule exceptions for O365, MS Teams, and Defender and also want to keep the firewall rules up to date.

    Here is a list of IPs for Office 365 URLs and IP address ranges. This list also includes Skype for Business Online and Microsoft Teams IPs.
    To manage access to O365 via the firewall, please refer to the Change Management for O365 IP addresses and URLs website. Changes to the Office 365 IP addresses and URLs are usually published near the last day of each month. Sometimes a change will be published outside of that schedule due to operational, support, or security requirements. Therefore, you can opt for one of the Change Management methods mentioned in the above document to get change notifications regarding the same.

    Hope this helps. Please let us know if you have any further questions and we will be glad to assist you further. Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.

    0 comments No comments