RM Logo
Technical Rating: 
Support Home PageSupport
Print This PagePrint This Page
Add to 'My Library' Add to 'My Library'

CC5 Deployment Network Requirements and Considerations
Published Date : 04 Aug 2026   Content Ref: TEC10542523  





Requirements

CC5 Endpoints

Master Allowlist Reference for CC5, Intune and Microsoft 365 Services
This list focuses on official Microsoft endpoint documentation.
You must ensure that the endpoints listed below are permitted through any filtering or firewall that you have configured. Failure to configure these ahead of builds or enrolments will cause failures.


Microsoft Intune
https://learn.microsoft.com/mem/intune/fundamentals/intune-endpoints

Intune device management (Android, iOS/iPadOS, Windows, macOS)
https://learn.microsoft.com/mem/intune/fundamentals/intune-endpoints#access-for-managed-devices

Microsoft Intune Suite / Endpoint Analytics
https://learn.microsoft.com/mem/intune/fundamentals/intune-endpoints#endpoint-analytics

Intune + Azure Front Door
https://learn.microsoft.com/mem/intune/fundamentals/intune-endpoints#azure-front-door

Office 365 URLs and IP address ranges
Master reference for Exchange Online, SharePoint Online, OneDrive, Teams, and Microsoft 365 common services. 
https://learn.microsoft.com/microsoft-365/enterprise/urls-and-ip-address-ranges

Microsoft Teams
https://learn.microsoft.com/microsoftteams/prepare-network

Media traffic (audio/video/screen sharing)
https://learn.microsoft.com/microsoftteams/prepare-network#media-traffic

Teams Rooms / Teams Phone / SIP gateway
https://learn.microsoft.com/microsoftteams/rooms/requirements 
https://learn.microsoft.com/microsoftteams/sip-gateway-plan

SharePoint Online
https://learn.microsoft.com/sharepoint/administration/endpoints

SharePoint Online and OneDrive domain requirements
https://learn.microsoft.com/sharepoint/administration/domains

OneDrive for Business
https://learn.microsoft.com/onedrive/plan-onedrive-network

OneDrive sync client endpoints
https://learn.microsoft.com/onedrive/onedrive-sync-client-network-requests

Exchange Online (required for Intune compliance policies)
https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/exchange-online-endpoints                             

Microsoft Entra ID (Azure AD) endpoints
https://learn.microsoft.com/azure/active-directory/fundamentals/azure-ad-endpoints

MSAL authentication endpoints
https://learn.microsoft.com/azure/active-directory/develop/msal-endpoints                                

Windows Update endpoints
https://learn.microsoft.com/windows/deployment/update/windows-update-troubleshooting#windows-update-network-requirements

Windows Autopilot network requirements
https://learn.microsoft.com/mem/autopilot/networking-requirements

Windows Autopatch endpoints
https://learn.microsoft.com/windows/deployment/windows-autopatch/network-requirements

Microsoft Defender for Endpoint
https://learn.microsoft.com/microsoft-365/security/defender-endpoint/configure-endpoints                                       


Service Tags (recommended instead of IP allowlists)
Azure service tags (including Intune, Microsoft 365, AAD, AFD)
https://learn.microsoft.com/azure/virtual-network/service-tags-overview
Downloadable JSON of all service tags
https://www.microsoft.com/download/details.aspx?id=56519




CC5, Intune and AutoPilot: Key Network & Security Considerations

TLS Inspection can often break AutoPilot deployments if not configured correctly, due to:

  • Autopilot and Intune heavy reliance on certificate pinning.
  • Many endpoints use HSTS + HPKP‑like behaviour.
  • Some services (notably Azure AD / Entra ID, Windows Update, Intune MDM, Autopilot) will reject re‑signed traffic, even if the proxy is trusted.

These categories should be bypassed from TLS inspection entirely:

Microsoft Entra ID (Azure AD)

  1. login.microsoftonline.com
  2. login.windows.net
  3. device.login.microsoftonline.com
  4. enterpriseregistration.windows.net
  5. device.login.microsoft.com
  6. aadcdn.msftauth.net
  7. aadcdn.msauth.net

If these are intercepted, you may experience:

  • Autopilot white‑screen hang
  • "Something went wrong" during OOBE
  • MDM enrollment failures
  • Conditional Access loops

Windows Autopilot

  1. ztd.dds.microsoft.com
  2. ztdgph.dds.microsoft.com
  3. cs.dds.microsoft.com

If these are intercepted, you may experience:

  • Device never downloads profile
  • Stuck at "Just a moment…"
  • Autopilot resets fail

Intune MDM + Enrollment

  1. manage.microsoft.com
  2. dm.microsoft.com
  3. enterpriseregistration.windows.net
  4. enrollment.manage.microsoft.com

If these are intercepted, you may experience:

  • Device enrolls but never syncs
  • Apps stuck at "Pending"
  • Compliance policies never apply

Windows Update / Store / Content Delivery

  1. *.windowsupdate.com
  2. *.update.microsoft.com
  3. *.delivery.mp.microsoft.com
  4. *.dl.delivery.mp.microsoft.com
  5. *.storeedgefd.dsx.mp.microsoft.com

If these are intercepted, you may experience:

  • Autopilot ESP hangs on "Installing apps"
  • Win32 apps never download
  • Feature updates fail

Microsoft 365 Core Services

  1. *.sharepoint.com
  2. *.office.com
  3. *.office365.com
  4. *.onenote.com
  5. *.teams.microsoft.com
  6. *.skype.com
  7. *.msedge.net

If these are intercepted, you may experience:

  • Teams sign‑in loops
  • OneDrive fails to authenticate
  • SharePoint pages fail to load
  • Office apps stuck at "Sign in required"

Miscellaneous Scripting Requirements

  1. www.powershellgallery.com
  2. powershellgallery.com
  3. psg-prod-eastus.azureedge.net 
  4. onegetcdn.azureedge.net 
  5. go.microsoft.com 
  6. aka.ms 
  7. login.microsoftonline.com 
  8. graph.microsoft.com

Proxy Authentication Considerations

As CC5 and Autopilot enrolment occurs before user signs-ins:

  • User‑based proxy auth will fail
  • Kerberos/NTLM challenges will fail
  • Captive portals will break the flow

In order to avoid above:

  • Device‑based authentication (certificate or IP‑based)
  • Transparent proxy mode
  • PAC file with direct bypass for Microsoft endpoints

Service Tags (recommended over FQDN/IP allowlists)

In order to avoid continuous maintenance:

  • Microsoft365
  • WindowsUpdate
  • Intune
  • AzureActiveDirectory
  • Autopilot
  • Office365
  • WindowsAutopatch

These are updated automatically by Microsoft and dramatically reduce breakage.

Autopilot Considerations

ESP (Enrollment Status Page)
ESP will hang indefinitely if TLS inspection or filtering blocks:

  • Win32 app downloads
  • Store content
  • Windows Update
  • Intune MDM sync

In order to address:

  1. Bypass inspection for all Microsoft CDN endpoints
  2. Ensure *.blob.core.windows.net is allowed
  3. Ensure *.azureedge.net is allowed

Win32 App Delivery
Win32 apps use:

  1. Intune MDM channel
  2. Azure CDN
  3. Delivery Optimization

If any of these are blocked, apps never install

Delivery Optimization
The following Delivery Optimization endpoints must be allowed:

  1. *.do.dsp.mp.microsoft.com
  2. *.dl.delivery.mp.microsoft.com

Note: Delivery Optimization will also fail under TLS inspection.

Certificate Pinning Summary

These Microsoft services use certificate pinning and cannot be intercepted:
ServiceTLS Inspection Allowed?Notes
Autopilot NoFails during OOBE
Intune MDNoFails during enrolment and synchronisation
Azure AD / Entra IDNoToken issuance fail
Windows UpdatesNoUpdates and ESP fail
Office 365NoMost endpoints will fail
TeamsNoMedia and authorisation will fail
OneDriveNo Synchronisation fail
SharePointNoModern authentication will fail



FEEDBACK
Did the information in this article help answer your question?
 Yes
 No
Please add any comments about this article in the box below. If you answered No then it is important you tell us why so that we can change the article if required. We can only respond if you log in to the RM Support website or provide your contact details. Note: If you need help with a technical query, please log a call online or telephone our support team.
Thank you for your feedback, which is sent directly to the RM Knowledge team. We address every message received with the intention of improving our Knowledge Library articles. If you have an unresolved technical issue, please contact RM Support.


If this article has not helped provide a solution then it is also possible to log a call...


Please read - important disclaimer information.
http://www.rm.com/_RMVirtual/Includes/csredirect.asp?cref=&title=Standard Content Disclaimer


Top Of PageTop of page