Regarding Endpoint security | Firewall rules configuration and limitations

MarcAF 105 Reputation points
2025-04-02T19:24:06.84+00:00

Hi,

I am exploring the configuration and limitations of Windows Server Firewall using Intune.

While configuring policies for firewall rules, I was wondering how would you implement outbound HTTP and HTTPS connections rules regarding public internet destinations?

  • I noted that "Reusable Settings" does not apply to Windows Servers.
  • From what I know, I cannot add FQDN for the remote targets.
  • Since, I cannot add FQDNs, I cannot add wildcards "*" in my destination.

For instance, how would you configure a rule for outbound HTTPS connections to Microsoft Updates Server with those targets:

From what I understand, the only way to do it seems to be to import a massive csv file in the destination field, which does not seems optimal.

Thank you

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
491 questions
0 comments No comments
{count} votes

Accepted answer
  1. Xenia-MSFT 5,870 Reputation points Microsoft External Staff
    2025-04-03T05:47:16.0933333+00:00

    @MarcAF Thanks for posting in our Q&A.

    For this issue, based on my check in outbound rules on windows server, there is no place to add FQDNs.

    Based on my research, the IP address for the Windows Update web site constantly changes and it is not a fixed address. Also, there is no official publication of the IP addresses. We still can't add IP address. So, there is no method to make it via Intune.

    Given this situation, did you consider deploying WSUS server to make it? We can point windows update to WSUS server, then we can connect to WSUS server to get windows update instead of connecting to Microsoft Updates Server.

    Hope it will give you some ideas.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.