Allow Microsoft Azure URLs
You must allow Microsoft Azure URLs to allow Microsoft Entra ID SSO authentication.
Allow URLs for all traffic
You must allow the following Microsoft Azure URLs for all traffic:
| Microsoft Azure URL |
|---|
*.aadcdn.microsoftonline-p.com |
*.login.live.com |
*.login.microsoftonline.com |
*.logincdn.msftauth.net |
*.microsoftonline-p.com |
*.msauth.net |
aadcdn.msftauth.net |
login.microsoft.com |
login.microsoftonline.com |
account.activedirectory.windowsazure.com |
*.aadcdn.msauthimages.net |
*.aadcdn.msftauthimages.net |
*.microsoftonline.com |
*.aadcdn.msftauth.net |
For the latest list of Microsoft Azure URLs, see Allow the Azure portal URLs on your firewall or proxy server.
Create an FQDN host
Do the following for each URL:
- Go to Hosts and services > FQDN host.
- Click Add.
- Enter the URL as the name.
- Enter the URL in FQDN.
- Click Save.
Create an FQDN host group
- Go to Hosts and services > FQDN host group.
- Click Add.
- Enter a name.
- Click Add new item and select the FQDN hosts you created.
- Click Save.
Create a firewall rule
- Go to Rules and policies > Firewall rules.
- Click IPv4 > Add firewall rule > New firewall rule.
-
Configure as follows:
Setting Value Rule name Enter a name. Action Accept Source zones LAN Source networks and devices Any Destination zones WAN Destination networks Select the FQDN host group you created. Services - DNS
- HTTPS
-
Click Save.
Direct web proxy mode
In direct web proxy mode, in addition to the firewall rules required for authentication, you must add the following Microsoft Azure URLs in a web exception:
| Microsoft Azure URL |
|---|
login\.microsoftonline\.com\.?/ |
^([A-Za-z0-9.-]*\.)?login.live.com\.?/ |
aadcdn\.msftauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn\.microsoftonline-p\.com\.?/ |
^([A-Za-z0-9.-]*\.)?login.microsoftonline.com\.?/ |
^([A-Za-z0-9.-]*\.)?logincdn.msftauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn.msauthimages.net\.?/ |
^([A-Za-z0-9.-]*\.)?.msauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn.msftauthimages.net\.?/ |
^([A-Za-z0-9.-]*\.)?microsoftonline\.com\.?/ |
^([A-Za-z0-9.-]*\.)?microsoftonline-p.com\.?/ |
^([A-Za-z0-9.-]*\.)?aadcdn.msftauth.net\.?/ |
^([A-Za-z0-9.-]*\.)?account.activedirectory.windowsazure.com\.?/ |
login\.microsoft\.com\.?/ |
To add the Microsoft Azure URLs in a web exception, do as follows:
- Go to Web > Exceptions and click Add an exception.
- Enter a name.
- Select URL pattern matches.
- Enter each URL in Search/Add and click Add
. - Select all the checks and actions.
- Click Save.