FQDN Tags.

Jessie 85 Reputation points
2023-12-12T04:54:17.8733333+00:00

Due to a change in Policy, we recently disabled internet access from our environment and are now not able to connect to SharePoint, and authentication to Micrsosoftonline also fails.

We are in favor of setting up Azure firewall Application rules that points to specific Sharepoint endpoints using FQDN tags, given the complexities with maintaining specific FQDNs.

However, we are unsure of which FQDN tags in the list available in Azure allows us to achieve both connecting to SharePoint and authenticating to Microsoftonline services.

Which FQDN tags should we enable?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,890 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
662 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,427 questions
SharePoint Server Management
SharePoint Server Management
SharePoint Server: A family of Microsoft on-premises document management and storage systems.Management: The act or process of organizing, handling, directing or controlling something.
2,941 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
    2023-12-14T04:52:50.44+00:00

    @Jessie

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    Different Microsoft O365 Services would require different URLs, FQDNs , IPs and Ports to be whitelisted.

    For a complete list of the configurations, refer : Office 365 URLs and IP address ranges.

    Some of the above can be achieved using Service tags in Azure Firewall.

    As described in Use Azure Firewall to protect Office 365.

    If a specific combination of product, category and required/not required has only FQDNs required, but uses TCP ports that aren't 80/443, an FQDN tag isn't be created for this combination. Application Rules can only cover HTTP, HTTPS or MSSQL

    Wrt SharePoint,

    With respect to AAD authentication,

    Cheers,

    Kapil


    Please Accept an answer if correct.

    Original posters help the community find answers faster by identifying the correct answer.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.