Recommended Free Tools
PowerShell scripts, Win32 apps, remediations, Endpoint Analytics, custom compliance policies and BIOS configuration profiles rely on the Intune Management Extension (IME), not just ordinary Intune enrollment. For Microsoft public-cloud tenants, that means allowing your tenant-region CDN hostnames over TCP 443, supporting HTTP partial responses, and—if you filter by IP or service tag—updating Azure Front Door rules introduced for Intune from December 2, 2025. The regional table below is current guidance; verify the live Microsoft endpoint page before changing production firewalls.
This article covers public-cloud tenants. US Government, GCC High, DoD and China tenants use different sovereign endpoints.
Which Intune workloads use these endpoints?
The requirement applies to Windows workloads delivered through the IME:
- Win32 application deployment
- PowerShell script deployment
- Remediations
- Endpoint Analytics
- Custom compliance policies
- BIOS configuration profiles
The IME is installed automatically when an assigned PowerShell script or Win32 app needs it. It checks for new Win32 assignments about hourly and after an Intune Management Extension service or device restart. A blocked connection can therefore look like a delayed assignment, “waiting for content,” a missing IME, or a failed download rather than an obvious firewall error. Microsoft’s Win32 overview is at learn.microsoft.com/en-us/intune/app-management/deployment/win32.
The deployment path
- Windows enrolls in Intune.
- An administrator assigns a script or Win32 app.
- Intune installs or activates the IME.
- The IME checks in and retrieves policy and content.
- The local agent runs the script or installer.
- Requirements, return codes and detection rules determine the result.
Find the tenant region first
In the Intune admin center, open Tenant administration → Tenant details → Tenant location. A value such as “North America 0501” should be mapped to the broad region shown in the table below, not treated as a separate endpoint family.
Required regional Scripts and Win32 Apps CDN endpoints
Microsoft documents these public-cloud hostnames for the IME content service. Allow all three names for the region, over TCP 443, and permit HTTP Partial Response (range requests and partial-content responses).
| Tenant region | Hostnames | Port and HTTP behavior |
|---|---|---|
| North America | imeswda-afd-primary.manage.microsoft.comimeswda-afd-secondary.manage.microsoft.comimeswda-afd-hotfix.manage.microsoft.com |
TCP 443; HTTP Partial Response required |
| Europe | imeswdb-afd-primary.manage.microsoft.comimeswdb-afd-secondary.manage.microsoft.comimeswdb-afd-hotfix.manage.microsoft.com |
TCP 443; HTTP Partial Response required |
| Asia Pacific | imeswdc-afd-primary.manage.microsoft.comimeswdc-afd-secondary.manage.microsoft.comimeswdc-afd-hotfix.manage.microsoft.com |
TCP 443; HTTP Partial Response required |
These names are only one part of Intune connectivity. Keep the broader endpoint list maintained at Microsoft’s Intune network endpoints documentation, rather than copying a static list into a firewall rule forever.
Rank #2
Additional Intune and Azure Front Door access
Common Intune FQDN patterns include *.delivery.mp.microsoft.com, *.dl.delivery.mp.microsoft.com, *.dm.microsoft.com, *.do.dsp.mp.microsoft.com, *.events.data.microsoft.com, *.manage.microsoft.com, *.monitor.azure.com, *.notify.windows.com, *.powershellgallery.com, *.s-microsoft.com, *.support.services.microsoft.com, *.trouter.communication.microsoft.com, *.trouter.communications.svc.cloud.microsoft, *.trouter.teams.microsoft.com and *.update.microsoft.com. The exact workload list changes, so use Microsoft’s live page.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Azure Front Door change
Microsoft says Intune network service endpoints began using Azure Front Door IP addresses on or shortly after December 2, 2025. If outbound traffic is filtered by IP address or Azure service tag, include ranges associated with AzureFrontDoor.MicrosoftSecurity and retain existing Intune rules while migrating. The diagnostic process checks outbound TCP 80 and 443 to Azure Front Door IP ranges; that does not change the regional CDN table’s documented TCP 443 requirement. See Microsoft Intune What’s new.
Older Office 365 endpoint scripts that attempted to calculate Intune IP addresses are no longer an authoritative source. Prefer FQDN-aware filtering or Microsoft-maintained service tags where your security platform supports them.
Proxy, firewall, VPN and TLS-inspection details
- Test the device context. The IME commonly runs as Local System, which may not have a signed-in user’s proxy credentials or route.
- Support large resumable downloads. Do not strip HTTP
Rangerequests or206 Partial Contentresponses; otherwise a large package can restart repeatedly. - Handle proxy authentication deliberately. Microsoft notes that some Intune tasks require unauthenticated proxy access to
manage.microsoft.com,*.azureedge.netandgraph.microsoft.com. This does not mean disabling authentication for every web user; provide a service-compatible path. - Check VPN routing and split tunneling. A tunnel that reaches management APIs but not CDN or Azure Front Door ranges can still break app content.
- Be cautious with TLS inspection. Follow endpoint-specific Microsoft guidance and test your appliance; some Intune-related services document SSL-inspection restrictions.
Store Win32 apps may need publisher domains
Intune is not necessarily the host for a Microsoft Store Win32 installer. The external publisher supplies an application-specific download location, and Microsoft may use a regional fallback cache. On a test Windows device, inspect the package with:
winget show [PackageId]
Review the Installer Url value and allow that publisher host when policy permits. An Intune CDN allowlist can be correct while the application’s own installer domain remains blocked.
Test connectivity from both user and SYSTEM contexts
Microsoft’s Test-IntuneAFDConnectivity.ps1 requires PowerShell 5.1 or later and tests DNS resolution, TCP 80/443 reachability to Azure Front Door IPs and HTTPS validation.
Rank #4
Standard and detailed tests
.Test-IntuneAFDConnectivity.ps1
.Test-IntuneAFDConnectivity.ps1 `
-LogLevel Detailed `
-OutputPath "C:Logs" `
-Verbose
Government-cloud test
.Test-IntuneAFDConnectivity.ps1 -CloudType gov
Local System test
Use PsExec to open a SYSTEM PowerShell window, then run the same script there:
.psexec.exe -accepteula -i -s powershell.exe
.Test-IntuneAFDConnectivity.ps1
A user-context success does not prove IME connectivity. Compare proxy logs, DNS answers, routes and firewall decisions for both identities.
Interpret common failures
| Symptom | Likely cause | Next check |
|---|---|---|
| Regional hostname will not resolve | DNS filtering, split DNS or stale resolver | Resolve the regional CDN and required Intune FQDNs from the endpoint |
| Azure Front Door IP test fails | Firewall, VPN, route or proxy blocks TCP 80/443 | Check service-tag/IP rules and device-context routing |
| HTTPS endpoint is unreachable | Missing FQDN, TLS inspection, proxy or DNS issue | Run the script as SYSTEM and inspect proxy/TLS logs |
| Download starts then restarts | Range or partial-content handling is broken | Verify HTTP Partial Response and resumable large downloads |
| IME never appears | Assignment, enrollment, licensing or check-in problem | Confirm scope and prerequisites before blaming the firewall |
| Content downloads but installer fails | Interactive installer, wrong command, permissions or architecture | Run the installer silently in the intended context |
| App installs but is marked failed | Detection rule, return code, dependency or context mismatch | Review detection and return-code logic |
| Store app fails only behind the firewall | Publisher installer URL is blocked | Run winget show [PackageId] and evaluate the Installer Url |
Network access is not the same as app prerequisites
For Win32 management, Microsoft lists supported Windows Enterprise, Pro or Education editions, Intune enrollment, and Microsoft Entra registered, joined or hybrid joined devices. A package can be up to 30 GB; an uploaded PowerShell installer script is limited to 50 KB. Intune-deployed applications must install silently, without dialogs or user input. See Microsoft’s Win32 app creation guidance.
Best Value
Choose the delivery model deliberately: a standalone PowerShell policy is suited to scripts and configuration, while a Win32 app adds packaged content, requirements, dependencies, retries, detection and Company Portal presentation. A Win32 app can also use a PowerShell installer script for prerequisite checks or conditional logic, running in the installer’s context and still subject to the 50-KB limit.
Public cloud, government and China tenants
The table in this article is for Microsoft public cloud. US Government, GCC High and DoD environments use sovereign names such as manage.microsoft.us; Microsoft Intune operated by 21Vianet uses China-specific endpoints, including imeswdsc-afd-pri.manage.microsoft.com. Use the dedicated US Government endpoint documentation and China endpoint documentation rather than substituting public-cloud names.
Quick Recap
Implementation checklist
- Record the tenant region in Tenant administration → Tenant details → Tenant location.
- Allow the region’s primary, secondary and hotfix CDN hostnames over TCP 443.
- Enable HTTP range requests and partial-content responses.
- Maintain the broader Intune FQDN requirements from Microsoft’s live endpoint page.
- If using IP or service-tag filtering, add Azure Front Door ranges associated with
AzureFrontDoor.MicrosoftSecurityand retain existing rules during transition. - Verify proxy, VPN and TLS behavior for Local System, not only an administrator’s browser.
- Run
Test-IntuneAFDConnectivity.ps1in user and SYSTEM contexts. - For Store Win32 apps, inspect publisher download URLs with
winget show [PackageId]. - Review IME logs under
C:ProgramDataMicrosoftIntuneManagementExtensionLogs, including download, policy, installation, detection and notification activity. - After network changes, reassess packaging, silent-install commands, requirements, dependencies, detection rules and return codes before escalating a deployment failure as a network fault.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

