Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PowerShell scripts, Win32 apps, remediations, Endpoint Analytics, custom compliance policies and BIOS configuration profiles rely on the Intune Management Extension (IME), not just ordinary Intune enrollment. For Microsoft public-cloud tenants, that means allowing your tenant-region CDN hostnames over TCP 443, supporting HTTP partial responses, and—if you filter by IP or service tag—updating Azure Front Door rules introduced for Intune from December 2, 2025. The regional table below is current guidance; verify the live Microsoft endpoint page before changing production firewalls.

This article covers public-cloud tenants. US Government, GCC High, DoD and China tenants use different sovereign endpoints.

Which Intune workloads use these endpoints?

The requirement applies to Windows workloads delivered through the IME:

  • Win32 application deployment
  • PowerShell script deployment
  • Remediations
  • Endpoint Analytics
  • Custom compliance policies
  • BIOS configuration profiles

The IME is installed automatically when an assigned PowerShell script or Win32 app needs it. It checks for new Win32 assignments about hourly and after an Intune Management Extension service or device restart. A blocked connection can therefore look like a delayed assignment, “waiting for content,” a missing IME, or a failed download rather than an obvious firewall error. Microsoft’s Win32 overview is at learn.microsoft.com/en-us/intune/app-management/deployment/win32.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The deployment path

  1. Windows enrolls in Intune.
  2. An administrator assigns a script or Win32 app.
  3. Intune installs or activates the IME.
  4. The IME checks in and retrieves policy and content.
  5. The local agent runs the script or installer.
  6. Requirements, return codes and detection rules determine the result.

Find the tenant region first

In the Intune admin center, open Tenant administration → Tenant details → Tenant location. A value such as “North America 0501” should be mapped to the broad region shown in the table below, not treated as a separate endpoint family.

Required regional Scripts and Win32 Apps CDN endpoints

Microsoft documents these public-cloud hostnames for the IME content service. Allow all three names for the region, over TCP 443, and permit HTTP Partial Response (range requests and partial-content responses).

Tenant region Hostnames Port and HTTP behavior
North America imeswda-afd-primary.manage.microsoft.com
imeswda-afd-secondary.manage.microsoft.com
imeswda-afd-hotfix.manage.microsoft.com
TCP 443; HTTP Partial Response required
Europe imeswdb-afd-primary.manage.microsoft.com
imeswdb-afd-secondary.manage.microsoft.com
imeswdb-afd-hotfix.manage.microsoft.com
TCP 443; HTTP Partial Response required
Asia Pacific imeswdc-afd-primary.manage.microsoft.com
imeswdc-afd-secondary.manage.microsoft.com
imeswdc-afd-hotfix.manage.microsoft.com
TCP 443; HTTP Partial Response required

These names are only one part of Intune connectivity. Keep the broader endpoint list maintained at Microsoft’s Intune network endpoints documentation, rather than copying a static list into a firewall rule forever.

Additional Intune and Azure Front Door access

Common Intune FQDN patterns include *.delivery.mp.microsoft.com, *.dl.delivery.mp.microsoft.com, *.dm.microsoft.com, *.do.dsp.mp.microsoft.com, *.events.data.microsoft.com, *.manage.microsoft.com, *.monitor.azure.com, *.notify.windows.com, *.powershellgallery.com, *.s-microsoft.com, *.support.services.microsoft.com, *.trouter.communication.microsoft.com, *.trouter.communications.svc.cloud.microsoft, *.trouter.teams.microsoft.com and *.update.microsoft.com. The exact workload list changes, so use Microsoft’s live page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Azure Front Door change

Microsoft says Intune network service endpoints began using Azure Front Door IP addresses on or shortly after December 2, 2025. If outbound traffic is filtered by IP address or Azure service tag, include ranges associated with AzureFrontDoor.MicrosoftSecurity and retain existing Intune rules while migrating. The diagnostic process checks outbound TCP 80 and 443 to Azure Front Door IP ranges; that does not change the regional CDN table’s documented TCP 443 requirement. See Microsoft Intune What’s new.

Older Office 365 endpoint scripts that attempted to calculate Intune IP addresses are no longer an authoritative source. Prefer FQDN-aware filtering or Microsoft-maintained service tags where your security platform supports them.

Proxy, firewall, VPN and TLS-inspection details

  • Test the device context. The IME commonly runs as Local System, which may not have a signed-in user’s proxy credentials or route.
  • Support large resumable downloads. Do not strip HTTP Range requests or 206 Partial Content responses; otherwise a large package can restart repeatedly.
  • Handle proxy authentication deliberately. Microsoft notes that some Intune tasks require unauthenticated proxy access to manage.microsoft.com, *.azureedge.net and graph.microsoft.com. This does not mean disabling authentication for every web user; provide a service-compatible path.
  • Check VPN routing and split tunneling. A tunnel that reaches management APIs but not CDN or Azure Front Door ranges can still break app content.
  • Be cautious with TLS inspection. Follow endpoint-specific Microsoft guidance and test your appliance; some Intune-related services document SSL-inspection restrictions.

Store Win32 apps may need publisher domains

Intune is not necessarily the host for a Microsoft Store Win32 installer. The external publisher supplies an application-specific download location, and Microsoft may use a regional fallback cache. On a test Windows device, inspect the package with:

winget show [PackageId]

Review the Installer Url value and allow that publisher host when policy permits. An Intune CDN allowlist can be correct while the application’s own installer domain remains blocked.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test connectivity from both user and SYSTEM contexts

Microsoft’s Test-IntuneAFDConnectivity.ps1 requires PowerShell 5.1 or later and tests DNS resolution, TCP 80/443 reachability to Azure Front Door IPs and HTTPS validation.

Standard and detailed tests

.Test-IntuneAFDConnectivity.ps1
.Test-IntuneAFDConnectivity.ps1 `
  -LogLevel Detailed `
  -OutputPath "C:Logs" `
  -Verbose

Government-cloud test

.Test-IntuneAFDConnectivity.ps1 -CloudType gov

Local System test

Use PsExec to open a SYSTEM PowerShell window, then run the same script there:

.psexec.exe -accepteula -i -s powershell.exe
.Test-IntuneAFDConnectivity.ps1

A user-context success does not prove IME connectivity. Compare proxy logs, DNS answers, routes and firewall decisions for both identities.

Interpret common failures

Symptom Likely cause Next check
Regional hostname will not resolve DNS filtering, split DNS or stale resolver Resolve the regional CDN and required Intune FQDNs from the endpoint
Azure Front Door IP test fails Firewall, VPN, route or proxy blocks TCP 80/443 Check service-tag/IP rules and device-context routing
HTTPS endpoint is unreachable Missing FQDN, TLS inspection, proxy or DNS issue Run the script as SYSTEM and inspect proxy/TLS logs
Download starts then restarts Range or partial-content handling is broken Verify HTTP Partial Response and resumable large downloads
IME never appears Assignment, enrollment, licensing or check-in problem Confirm scope and prerequisites before blaming the firewall
Content downloads but installer fails Interactive installer, wrong command, permissions or architecture Run the installer silently in the intended context
App installs but is marked failed Detection rule, return code, dependency or context mismatch Review detection and return-code logic
Store app fails only behind the firewall Publisher installer URL is blocked Run winget show [PackageId] and evaluate the Installer Url
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Network access is not the same as app prerequisites

For Win32 management, Microsoft lists supported Windows Enterprise, Pro or Education editions, Intune enrollment, and Microsoft Entra registered, joined or hybrid joined devices. A package can be up to 30 GB; an uploaded PowerShell installer script is limited to 50 KB. Intune-deployed applications must install silently, without dialogs or user input. See Microsoft’s Win32 app creation guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the delivery model deliberately: a standalone PowerShell policy is suited to scripts and configuration, while a Win32 app adds packaged content, requirements, dependencies, retries, detection and Company Portal presentation. A Win32 app can also use a PowerShell installer script for prerequisite checks or conditional logic, running in the installer’s context and still subject to the 50-KB limit.

Public cloud, government and China tenants

The table in this article is for Microsoft public cloud. US Government, GCC High and DoD environments use sovereign names such as manage.microsoft.us; Microsoft Intune operated by 21Vianet uses China-specific endpoints, including imeswdsc-afd-pri.manage.microsoft.com. Use the dedicated US Government endpoint documentation and China endpoint documentation rather than substituting public-cloud names.

Implementation checklist

  1. Record the tenant region in Tenant administration → Tenant details → Tenant location.
  2. Allow the region’s primary, secondary and hotfix CDN hostnames over TCP 443.
  3. Enable HTTP range requests and partial-content responses.
  4. Maintain the broader Intune FQDN requirements from Microsoft’s live endpoint page.
  5. If using IP or service-tag filtering, add Azure Front Door ranges associated with AzureFrontDoor.MicrosoftSecurity and retain existing rules during transition.
  6. Verify proxy, VPN and TLS behavior for Local System, not only an administrator’s browser.
  7. Run Test-IntuneAFDConnectivity.ps1 in user and SYSTEM contexts.
  8. For Store Win32 apps, inspect publisher download URLs with winget show [PackageId].
  9. Review IME logs under C:ProgramDataMicrosoftIntuneManagementExtensionLogs, including download, policy, installation, detection and notification activity.
  10. After network changes, reassess packaging, silent-install commands, requirements, dependencies, detection rules and return codes before escalating a deployment failure as a network fault.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.