Firewall rules to sync Office 365 calendar to on-prem Exchange server

fred 21 Reputation points
2020-09-17T22:06:59.4+00:00

My company is beginning a project to use Azure, InTune, Teams, and some calendar syncing between O365 and on-premise Exchange. This project requires Microsoft to have access to our autodiscover URL. Is there a document that explains what firewall rules are needed for this?

Our firewall admins were told to allow access from the Office 365 URLs and IP address ranges listed here (https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide). That seems like a lot of IPs. Are those IPs strictly used by Microsoft's internal infrastructure? Or could Company XYZ, or hacker John Doe, using O365 or an Azure service like a virtual workstation also source from those IP addresses? Trying to understand the risk of allowing inbound access from all the IPs in that document.

Any information is appreciated.

Regards,
Fred

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,211 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 142.3K Reputation points MVP
    2020-09-17T22:10:35.09+00:00

    Strictly used by Microsoft infrastructure from Exchange Online. Those IPs are not available to from a Azure workstation or other process.
    And I have full trust in Microsoft's ability to protect those IPs for that purpose, not just saying that, but mean it. They take this stuff seriously.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Lydia Zhou - MSFT 2,371 Reputation points Microsoft Employee
    2020-09-18T07:12:04.24+00:00

    anonymous user-0179

    Agree with AndyDavid, that official document is trustworthy and make sure the needed endpoint sets are not blocked.

    Additionally, do you have to deploy the hybrid? You can check this article for more information about Hybrid deployment protocols, ports, and endpoints, and the link you provided is also included in it.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments