Action required: Allow new Windows App client-side endpoints for Windows 365
🚨 The Signal: Windows App for Windows 365 will use new client-side FQDNs starting October 2026. Organisations must update client-side network controls (firewall, proxy, DNS) to allow these endpoints, or users will face connection failures. This is critical for maintaining access to Cloud PCs.
The Impact
Organisations using Windows App for Windows 365 are affected, risking service disruption and non-compliance if network controls are not updated.
- Security Teams: Must update network security policies to allow new FQDNs.
- Network Admins: Required to configure firewalls, proxies, and DNS filters.
- End Users: May experience connection failures if network updates are not completed.
- Compliance Teams: Risk of non-compliance with network security standards.
The Action
- Identify all client-side network controls (firewall, proxy, VPN, DNS filtering, Secure Web Gateway) affecting Windows App users.
- Add '*.windows.cloud.microsoft' on port 443/TCP to allowed outbound rules.
- Add '*.service.windows.cloud.microsoft' on port 443/TCP to allowed outbound rules.
- Add '*.windows.static.microsoft' on port 443/TCP to allowed outbound rules.
- Test connectivity for Windows App users to Windows 365 Cloud PCs after implementing changes.
Domain: Other · Impact: high · Workload: Other