blocklists:microsoft:microsoft_office_365
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
blocklists:microsoft:microsoft_office_365 [2021/02/07 19:04] – [Get Current List of IP Addresses] peter | blocklists:microsoft:microsoft_office_365 [2021/02/11 10:19] (current) – peter | ||
---|---|---|---|
Line 9: | Line 9: | ||
<WRAP info> | <WRAP info> | ||
- | **NOTE: | + | **NOTE: |
- | + | ||
- | See: [[Blocklists: | + | |
</ | </ | ||
Line 72: | Line 70: | ||
---- | ---- | ||
- | ==== Ports ==== | + | ===== Get Current List of URLs ===== |
- | For chat: | + | <code bash> |
+ | jq -r '.[] | select(.urls) .urls[]' | ||
+ | </ | ||
- | * http (80) | + | returns: |
- | * https (443) | + | |
- | * udp/ | + | |
- | + | ||
- | + | ||
- | ---- | + | |
- | + | ||
- | ===== Domain list ===== | + | |
< | < | ||
- | office.com | + | *.aadrm.com |
- | office365.com | + | account.activedirectory.windowsazure.com |
- | office.net | + | account.live.com |
- | onedrive.com | + | account.office.net |
- | sharepoint.com | + | accounts.accesscontrol.windows.net |
- | optimizely.com | + | accounts.google.com |
- | microsoftonline.com | + | acompli.helpshift.com |
- | production.us.trafficmanager.net | + | *.acompli.net |
- | microsoft.com | + | activation.sls.microsoft.com |
- | live.com | + | activity.windows.com |
+ | ad.atdmt.com | ||
+ | *.adl.windows.com | ||
+ | admin.microsoft.com | ||
+ | admin.onedrive.com | ||
+ | adminwebservice.microsoftonline.com | ||
+ | ajax.aspnetcdn.com | ||
+ | ajax.microsoft.com | ||
+ | aka.ms | ||
+ | amp.azure.net | ||
+ | amsglob0cdnstream13.azureedge.net | ||
+ | amsglob0cdnstream14.azureedge.net | ||
+ | analytics.localytics.com | ||
+ | api.dropboxapi.com | ||
+ | api.localytics.com | ||
+ | api.login.yahoo.com | ||
+ | api.meetup.com | ||
+ | *.api.microsoftstream.com | ||
+ | api.microsoftstream.com | ||
+ | api.office.com | ||
+ | api.passwordreset.microsoftonline.com | ||
+ | apis.live.net | ||
+ | app.adjust.com | ||
+ | app.box.com | ||
+ | *.appex.bing.com | ||
+ | *.appex-rf.msn.com | ||
+ | appsforoffice.microsoft.com | ||
+ | apps.identrust.com | ||
+ | *.aria.microsoft.com | ||
+ | assets.onestore.ms | ||
+ | *.assets-yammer.com | ||
+ | attachments.office.net | ||
+ | auth.gfx.ms | ||
+ | autodiscover.*.onmicrosoft.com | ||
+ | autologon.microsoftazuread-sso.com | ||
+ | *.azure-apim.net | ||
+ | *.azureedge.net | ||
+ | *.azurerms.com | ||
+ | becws.microsoftonline.com | ||
+ | bit.ly | ||
+ | *.blob.core.windows.net | ||
+ | *.broadcast.skype.com | ||
+ | broadcast.skype.com | ||
+ | by.uservoice.com | ||
+ | c1.microsoft.com | ||
+ | cacerts.digicert.com | ||
+ | c.bing.com | ||
+ | c.bing.net | ||
+ | cdn.forms.office.net | ||
+ | cdn.odc.officeapps.live.com | ||
+ | *.cdn.office.net | ||
+ | *cdn.onenote.net | ||
+ | cdn.optimizely.com | ||
+ | cdnprod.myanalytics.microsoft.com | ||
+ | cdn.sharepointonline.com | ||
+ | cert.int-x3.letsencrypt.org | ||
+ | cl2.apple.com | ||
+ | clientconfig.microsoftonline-p.net | ||
+ | c.live.com | ||
+ | *.cloudapp.net | ||
+ | companymanager.microsoftonline.com | ||
+ | compass-ssl.microsoft.com | ||
+ | *.config.office.net | ||
+ | connect.facebook.net | ||
+ | contentstorage.osi.office.net | ||
+ | crl3.digicert.com | ||
+ | crl4.digicert.com | ||
+ | crl.globalsign.com | ||
+ | crl.globalsign.net | ||
+ | crl.identrust.com | ||
+ | crl.microsoft.com | ||
+ | data.flurry.com | ||
+ | dc.applicationinsights.microsoft.com | ||
+ | dc.services.visualstudio.com | ||
+ | d.docs.live.net | ||
+ | device.login.microsoftonline.com | ||
+ | dgps.support.microsoft.com | ||
+ | directory.services.live.com | ||
+ | docs.live.net | ||
+ | docs.microsoft.com | ||
+ | ecn.dev.virtualearth.net | ||
+ | enterpriseregistration.windows.net | ||
+ | *.entrust.net | ||
+ | en-us.appex-rf.msn.com | ||
+ | eus-www.sway-cdn.com | ||
+ | eus-www.sway-extensions.com | ||
+ | *.events.data.microsoft.com | ||
+ | excelbingmap.firstpartyapps.oaspapps.com | ||
+ | excelcs.officeapps.live.com | ||
+ | *-files.sharepoint.com | ||
+ | firstpartyapps.oaspapps.com | ||
+ | *.flow.microsoft.com | ||
+ | foodanddrink.services.appex.bing.com | ||
+ | forms.microsoft.com | ||
+ | *.geotrust.com | ||
+ | g.live.com | ||
+ | go.microsoft.com | ||
+ | graph.facebook.com | ||
+ | graph.microsoft.com | ||
+ | graph.windows.net | ||
+ | *.helpshift.com | ||
+ | *.hip.live.com | ||
+ | *.hockeyapp.net | ||
+ | home.office.com | ||
+ | *.informationprotection.azure.com | ||
+ | informationprotection.hosting.portal.azure.net | ||
+ | insertmedia.bing.office.net | ||
+ | isrg.trustid.ocsp.identrust.com | ||
+ | *.itunes.apple.com | ||
+ | *.keydelivery.mediaservices.windows.net | ||
+ | *.localytics.com | ||
+ | logincert.microsoftonline.com | ||
+ | loginex.microsoftonline.com | ||
+ | login.live.com | ||
+ | login.microsoft.com | ||
+ | login.microsoftonline.com | ||
+ | login.microsoftonline-p.com | ||
+ | login-us.microsoftonline.com | ||
+ | login.windows.net | ||
+ | login.windows-ppe.net | ||
+ | *.log.optimizely.com | ||
+ | lpcres.delve.office.com | ||
+ | *.lync.com | ||
+ | mail.google.com | ||
+ | *.mail.protection.outlook.com | ||
+ | management.azure.com | ||
+ | *.manage.microsoft.com | ||
+ | *.manage.office.com | ||
+ | manage.office.com | ||
+ | *.media.azure.net | ||
+ | mem.gfx.ms | ||
+ | m.facebook.com | ||
+ | *.microsoft.com | ||
+ | *.microsoftonline.com | ||
+ | *.microsoftonline-p.com | ||
+ | *.microsoftusercontent.com | ||
+ | mlccdn.blob.core.windows.net | ||
+ | mlccdnprod.azureedge.net | ||
+ | mrodevicemgr.officeapps.live.com | ||
+ | *.msauthimages.net | ||
+ | *.msauth.net | ||
+ | mscrl.microsoft.com | ||
+ | msdn.microsoft.com | ||
+ | *.msecnd.net | ||
+ | *.msedge.net | ||
+ | *.msftauthimages.net | ||
+ | *.msftauth.net | ||
+ | *.msftidentity.com | ||
+ | *.msidentity.com | ||
+ | *.msocdn.com | ||
+ | *.mstea.ms | ||
+ | myanalytics-gcc.microsoft.com | ||
+ | myanalytics.microsoft.com | ||
+ | *-myfiles.sharepoint.com | ||
+ | nexus.microsoftonline-p.com | ||
+ | nexus.officeapps.live.com | ||
+ | nexusrules.officeapps.live.com | ||
+ | *.notification.api.microsoftstream.com | ||
+ | nps.onyx.azure.net | ||
+ | o15.officeredir.microsoft.com | ||
+ | *.o365weve.com | ||
+ | ocos-office365-s2s.msedge.net | ||
+ | ocsa.officeapps.live.com | ||
+ | ocsp2.globalsign.com | ||
+ | ocsp.digicert.com | ||
+ | ocsp.globalsign.com | ||
+ | ocsp.int-x3.letsencrypt.org | ||
+ | ocsp.msocsp.com | ||
+ | ocspx.digicert.com | ||
+ | ocsredir.officeapps.live.com | ||
+ | ocws.officeapps.live.com | ||
+ | odc.officeapps.live.com | ||
+ | odcsm.officeapps.live.com | ||
+ | office15client.microsoft.com | ||
+ | *.office365.com | ||
+ | office365servicehealthcommunications.cloudapp.net | ||
+ | *.officeapps.live.com | ||
+ | officeapps.live.com | ||
+ | officecdn.microsoft.com | ||
+ | officecdn.microsoft.com.edgesuite.net | ||
+ | officeclient.microsoft.com | ||
+ | *.office.com | ||
+ | *.officeconfig.msocdn.com | ||
+ | office.live.com | ||
+ | office.microsoft.com | ||
+ | *.office.net | ||
+ | officepreviewredir.microsoft.com | ||
+ | officeredir.microsoft.com | ||
+ | officespeech.platform.bing.com | ||
+ | ols.officeapps.live.com | ||
+ | omextemplates.content.office.net | ||
+ | *.omniroot.com | ||
oneclient.sfx.ms | oneclient.sfx.ms | ||
- | sharepointonline.com | + | *.onenote.com |
- | spoprod-a.akamaihd.net | + | *.online.office.com |
+ | *.onmicrosoft.com | ||
+ | osiprod-cus-daffodil-signalr-00.service.signalr.net | ||
+ | osiprod-neu-daffodil-signalr-00.service.signalr.net | ||
+ | osiprod-weu-daffodil-signalr-00.service.signalr.net | ||
+ | osiprod-wus-daffodil-signalr-00.service.signalr.net | ||
+ | *.outlook.com | ||
+ | *.outlookmobile.com | ||
+ | outlook.office365.com | ||
+ | *.outlook.office.com | ||
+ | outlook.office.com | ||
+ | outlook.uservoice.com | ||
+ | p100-sandbox.itunes.apple.com | ||
+ | partnerservices.getmicrosoftkey.com | ||
+ | passwordreset.microsoftonline.com | ||
+ | peoplegraph.firstpartyapps.oaspapps.com | ||
+ | *.phonefactor.net | ||
+ | platform.linkedin.com | ||
+ | play.google.com | ||
+ | policykeyservice.dc.ad.msft.net | ||
+ | *.portal.cloudappsecurity.com | ||
+ | portal.microsoftonline.com | ||
+ | portal.office.com | ||
+ | *.powerapps.com | ||
+ | pptcs.officeapps.live.com | ||
+ | privatecdn.sharepointonline.com | ||
+ | prod.firstpartyapps.oaspapps.com.akadns.net | ||
prod.msocdn.com | prod.msocdn.com | ||
- | svc.ms | + | *.protection.office.com |
- | lync.com | + | protection.office.com |
- | broadcast.skype.com | + | *.protection.outlook.com |
- | skypeforbusiness.com | + | provisioningapi.microsoftonline.com |
- | sfbassets.com | + | publiccdn.sharepointonline.com |
+ | *.public-trust.com | ||
+ | r1.res.office365.com | ||
+ | r3.res.office365.com | ||
+ | r3.res.outlook.com | ||
+ | r4.res.office365.com | ||
+ | rink.hockeyapp.net | ||
+ | roaming.officeapps.live.com | ||
+ | r.office.microsoft.com | ||
+ | s0.assets-yammer.com | ||
+ | sas.office.microsoft.com | ||
+ | sdk.hockeyapp.net | ||
+ | *.search.production.apac.trafficmanager.net | ||
+ | *.search.production.emea.trafficmanager.net | ||
+ | *.search.production.us.trafficmanager.net | ||
+ | secure.aadcdn.microsoftonline-p.com | ||
+ | secure.globalsign.com | ||
+ | secure.meetup.com | ||
+ | *.secure.skypeassets.com | ||
+ | *.sfbassets.com | ||
+ | *.sharepoint.com | ||
+ | *.sharepointonline.com | ||
+ | shellprod.msocdn.com | ||
+ | signup.live.com | ||
+ | signup.microsoft.com | ||
+ | *.skype.com | ||
+ | *.skypeforbusiness.com | ||
skypemaprdsitus.trafficmanager.net | skypemaprdsitus.trafficmanager.net | ||
- | windows.net | + | smtp.office365.com |
- | msecnd.net | + | social.yahooapis.com |
- | aspnetcdn.com | + | spoprod-a.akamaihd.net |
- | live.net | + | ssw.live.com |
- | aka.ms | + | |
- | azure.net | + | |
- | windows.com | + | |
- | windows.net | + | |
- | msedge.net | + | |
- | mstea.ms | + | |
- | skypeassets.com | + | |
- | azureedge.net | + | |
- | tenor.com | + | |
- | microsoftstream.com | + | |
- | assets-yammer.com | + | |
- | azureedge.net | + | |
- | onenote.com | + | |
- | onenote.net | + | |
- | aspnetcdn.com | + | |
- | optimizely.com | + | |
- | msappproxy.net | + | |
- | msftidentity.com | + | |
- | msidentity.com | + | |
- | windowsazure.com | + | |
- | microsoftazuread-sso.com | + | |
- | microsoftonline-p.net | + | |
- | msauth.net | + | |
- | msauthimages.net | + | |
- | msftauth.net | + | |
- | msftauthimages.net | + | |
- | phonefactor.net | + | |
- | visualstudio.com | + | |
- | cloudapp.net | + | |
staffhub.ms | staffhub.ms | ||
- | gfx.ms | + | staffhub.uservoice.com |
- | appex.bing.com | + | staffhubweb.azureedge.net |
- | appex-rf.msn.com | + | static.sharepointonline.com |
- | getmicrosoftkey.com | + | statics.teams.microsoft.com |
- | atdmt.com | + | storage.live.com |
- | yammer.com | + | *.streaming.mediaservices.windows.net |
- | yammerusercontent.com | + | suite.office.net |
- | sway-cdn.com | + | support.content.office.net |
- | sway-extensions.com | + | support.microsoft.com |
+ | support.office.com | ||
+ | *.svc.ms | ||
sway.com | sway.com | ||
+ | *.symcb.com | ||
+ | *.symcd.com | ||
+ | s.ytimg.com | ||
+ | *.teams.microsoft.com | ||
+ | teams.microsoft.com | ||
+ | technet.microsoft.com | ||
+ | telemetryservice.firstpartyapps.oaspapps.com | ||
+ | *.tenor.com | ||
+ | testconnectivity.microsoft.com | ||
+ | tse1.mm.bing.net | ||
+ | uci.officeapps.live.com | ||
+ | *.urlp.sfbassets.com | ||
+ | *.users.storage.live.com | ||
+ | *.verisign.com | ||
+ | *.verisign.net | ||
+ | videocontent.osi.office.net | ||
+ | videoplayercdn.osi.office.net | ||
+ | view.atdmt.com | ||
+ | *.virtualearth.net | ||
+ | vortex.data.microsoft.com | ||
+ | watson.microsoft.com | ||
+ | watson.telemetry.microsoft.com | ||
+ | weather.tile.appex.bing.com | ||
+ | webanalytics.localytics.com | ||
+ | web.localytics.com | ||
+ | web.microsoftstream.com | ||
+ | wikipedia.firstpartyapps.oaspapps.com | ||
+ | *.wns.windows.com | ||
+ | wordcs.officeapps.live.com | ||
+ | workplaceanalytics.cdn.office.net | ||
+ | workplaceanalytics.office.com | ||
+ | wus-firstpartyapps.oaspapps.com | ||
+ | wus-www.sway-cdn.com | ||
+ | wus-www.sway-extensions.com | ||
+ | www.acompli.com | ||
+ | www.bing.com | ||
+ | www.digicert.com | ||
+ | www.dropbox.com | ||
+ | www.evernote.com | ||
+ | www.google-analytics.com | ||
+ | www.googleapis.com | ||
+ | www.microsoft.com | ||
+ | www.office.com | ||
+ | www.onedrive.com | ||
+ | www.outlook.com | ||
+ | www.sway.com | ||
+ | www.youtube.com | ||
+ | *.yammer.com | ||
+ | *.yammerusercontent.com | ||
+ | </ | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== Get Current List of TCP Ports ===== | ||
+ | |||
+ | <code bash> | ||
+ | jq -r '.[] | .tcpPorts' | ||
+ | </ | ||
+ | |||
+ | returns: | ||
+ | |||
+ | < | ||
+ | 143 | ||
+ | 25 | ||
+ | 443 | ||
+ | 587 | ||
+ | 80 | ||
+ | 993 | ||
+ | 995 | ||
+ | null | ||
</ | </ | ||
<WRAP info> | <WRAP info> | ||
- | **NOTE: | + | **NOTE: |
- | For example, excel.officeapps.microsoft.com, | + | <code bash> |
- | + | jq -r '.[] | .tcpPorts' | |
- | Amend if needed. | + | </ |
</ | </ | ||
Line 163: | Line 442: | ||
---- | ---- | ||
- | ==== IP Ranges | + | ===== Get Current List of UDP Ports ===== |
- | Includes local subnets if not present already. | + | <code bash> |
+ | jq -r '.[] | .udpPorts' | ||
+ | </ | ||
+ | |||
+ | returns: | ||
< | < | ||
- | 104.146.128.0/ | + | 3478 |
- | 104.42.230.91 | + | 3479 |
- | 104.44.218.128/ | + | 3480 |
- | 104.44.254.128/ | + | 3481 |
- | 104.44.255.0/ | + | null |
- | 104.47.0.0/ | + | |
- | 13.91.91.243 | + | |
- | 13.106.4.128/ | + | |
- | 13.106.56.0/ | + | |
- | 13.107.128.0/ | + | |
- | 13.107.136.0/ | + | |
- | 13.107.140.6 | + | |
- | 13.107.18.10/ | + | |
- | 13.107.6.152/ | + | |
- | 13.107.6.156/ | + | |
- | 13.107.6.171 | + | |
- | 13.107.7.190/ | + | |
- | 13.107.9.155/ | + | |
- | 13.80.125.22 | + | |
- | 131.253.33.215 | + | |
- | 132.245.0.0/ | + | |
- | 134.170.172.128/ | + | |
- | 134.170.67.0/ | + | |
- | 150.171.32.0/ | + | |
- | 150.171.40.0/ | + | |
- | 157.55.130.0/ | + | |
- | 157.55.145.0/ | + | |
- | 157.55.155.0/ | + | |
- | 157.55.227.192/ | + | |
- | 157.55.45.128/ | + | |
- | 191.232.2.128/ | + | |
- | 191.234.140.0/ | + | |
- | 20.190.128.0/ | + | |
- | 204.79.197.215 | + | |
- | 23.103.160.0/ | + | |
- | 40.96.0.0/ | + | |
- | 40.104.0.0/ | + | |
- | 40.107.0.0/ | + | |
- | 40.108.128.0/ | + | |
- | 40.126.0.0/ | + | |
- | 40.81.156.154 | + | |
- | 40.92.0.0/ | + | |
- | 40.90.218.198 | + | |
- | 52.108.0.0/ | + | |
- | 52.100.0.0/ | + | |
- | 52.104.0.0/ | + | |
- | 52.174.56.180 | + | |
- | 52.183.75.62 | + | |
- | 52.184.165.82 | + | |
- | 52.238.106.116 | + | |
- | 52.238.78.88 | + | |
- | 52.247.150.191 | + | |
- | 52.96.0.0/ | + | |
- | 65.54.170.128/ | + | |
</ | </ | ||
- | ---- | + | <WRAP info> |
+ | **NOTE: | ||
- | For the Teams app, these additional IP ranges are needed: | + | < |
- | + | jq -r '.[] | .udpPorts' | |
- | < | + | |
- | 13.107.64.0/ | + | |
- | 52.112.0.0/ | + | |
- | 52.120.0.0/14 | + | |
</ | </ | ||
+ | |||
+ | </ | ||
---- | ---- | ||
Line 245: | Line 478: | ||
https:// | https:// | ||
+ | |||
+ | https:// |
blocklists/microsoft/microsoft_office_365.1612724690.txt.gz · Last modified: 2021/02/07 19:04 by peter