azure Azure Updates ·

Announcing Required Client-Side Endpoints for AVD Windows App

networkingazureengineer
announcement breaking

Microsoft announced that the Windows App for Azure Virtual Desktop will begin utilizing three new wildcard fully qualified domain names (FQDNs) for client-side service traffic starting in early October 2026. Organizations that implement network controls on user devices must allow outbound HTTPS traffic on port 443/TCP to `*.windows.cloud.microsoft`, `*.service.windows.cloud.microsoft`, and `*.windows.static.microsoft`. Failure to configure these network endpoints could lead to sign-in, resource discovery, or connection failures for users. This change is part of a broader effort to unify Microsoft domain requirements and requires action before the specified deadline.

Notes (1)
  • Future Required Client-Side Endpoints for Windows App

    Starting early October 2026, Windows App for Azure Virtual Desktop will use three new wildcard FQDNs: `*.windows.cloud.microsoft`, `*.service.windows.cloud.microsoft`, and `*.windows.static.microsoft` for client-side traffic. Organizations must ensure outbound HTTPS traffic on port 443/TCP is allowed to these domains in firewall, proxy, VPN, DNS filtering, and Secure Web Gateway policies on user devices to prevent service disruption. This change is distinct from previous cloud-side updates.

Read the original announcement →

https://azure.microsoft.com/updates?id=571360

Related releases