How to limit or control the outbound IP addresses used by Entra ID for authentication?

NaviCoding 45 Reputation points
2024-08-14T09:50:06.05+00:00

I am looking for a solution or some kind of work-around regarding the amount of IP-addresses that Entra ID uses for redundancy. I want to somehow control or limit which IP-addresses are used for the outbound traffic when the DNS (login.microsoftonline.com) OAuth2-JWKSURL endpoint resolves the IP address.

We have a system which has Geo-based DDoS protection and it only allows traffic from selected IP addresses, and opening it up for the 600k + dynamically changing IP addresses that Entra ID has is not an option.

Is there a way to control or limit the IP addresses to either specific ones or based on region? Using VNets, LAs or something?

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
2,074 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.