Allow Microsoft Azure URLs
You must allow Microsoft Azure URLs to allow Microsoft Entra ID (Azure AD) SSO (Single sign-on) authentication.
Allow URLs for all traffic
You must allow the following Microsoft Azure URLs for all traffic:
Microsoft Azure URL |
---|
*.aadcdn.microsoftonline-p.com |
*.login.live.com |
*.login.microsoftonline.com |
*.logincdn.msftauth.net |
*.microsoftonline-p.com |
*.msauth.net |
aadcdn.msftauth.net |
login.microsoft.com |
login.microsoftonline.com |
account.activedirectory.windowsazure.com |
*.aadcdn.msauthimages.net |
*.aadcdn.msftauthimages.net |
*.microsoftonline.com |
*.aadcdn.msftauth.net |
For the latest list of Microsoft Azure URLs, see Allow the Azure portal URLs on your firewall or proxy server.
Create an FQDN host
Do the following for each URL:
- Go to Hosts and services > FQDN host.
- Click Add.
- Enter the URL as the name.
- Enter the URL in FQDN.
- Click Save.
Create an FQDN host group
- Go to Hosts and services > FQDN host group.
- Click Add.
- Enter a name.
- Click Add new item and select the FQDN hosts you created.
- Click Save.
Create a firewall rule
- Go to Rules and policies > Firewall rules.
- Click IPv4 > Add firewall rule > New firewall rule.
-
Configure as follows:
Setting Value Rule name Enter a name. Action Accept Source zones LAN Source networks and devices Any Destination zones WAN Destination networks Select the FQDN host group you created. Services - DNS
- HTTPS
-
Click Save.
Direct web proxy mode
In direct web proxy mode, in addition to the firewall rules required for authentication, you must add the following Microsoft Azure URLs in a web exception:
Microsoft Azure URL |
---|
login\.microsoftonline\.com\.?/ |
^([A-Za-z0-9.-]*\.)?login.live.com\.?/ |
aadcdn\.msftauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn\.microsoftonline-p\.com\.?/ |
^([A-Za-z0-9.-]*\.)?login.microsoftonline.com\.?/ |
^([A-Za-z0-9.-]*\.)?logincdn.msftauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn.msauthimages.net\.?/ |
^([A-Za-z0-9.-]*\.)?.msauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn.msftauthimages.net\.?/ |
^([A-Za-z0-9.-]*\.)?microsoftonline\.com\.?/ |
^([A-Za-z0-9.-]*\.)?microsoftonline-p.com\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn.msftauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?account.activedirectory.windowsazure.com\.?/ |
login\.microsoft\.com\.?/ |
To add the Microsoft Azure URLs in a web exception, do as follows:
- Go to Web > Exceptions and click Add an exception.
- Enter a name.
- Select URL pattern matches.
- Enter each URL in Search/Add and click Add .
- Select all the checks and actions.
- Click Save.