Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.
Windows Update requires TCP port 80, 443, and 49152-65535.
The IP address for the Windows Update web site constantly changes and it is not a fixed address. Also, there is no official publication of the IP addresses. We normally advise against defining IP addresses on the firewall for this purpose. Instead, we suggest either allowing all outbound connections to http & https ports.
If you can use Service Tags instead, look for AzureUpdateDelivery tag here: https://video2.skills-academy.com/en-us/azure/virtual-network/service-tags-overview
Cheers,
Rohith.
Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.