Updated network requirements for GCC and Gov customers
July 2025
Updated network requirements for GCC and Gov customers
To support ongoing security enhancements and maintain service availability, Microsoft Defender for Cloud Apps now requires updated firewall configurations for customers in GCC and Gov environments.
To avoid service disruption, take action by August 25, 2025, and update your firewall configuration as follows:
Allow outbound traffic on port 443 to the following IP ranges:
- 51.54.53.136/29
- 51.54.114.160/29
- 62.11.173.176/29
If you're using Azure service tags, add AzureFrontDoor.MicrosoftSecurity to your firewall allowlist.
Add the following endpoint to your firewall allowlist on port 443:
discoveryresources-cdn-prod.cloudappsecurity.com
For the full list of required IP addresses and endpoints, see Network requirements.