Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Action required: Allow new Windows App client-side endpoints for Windows 365

Message ID
MC1461151
View in Message Center
Service
Windows 365
Category
Plan for Change
Tags
Major Change Admin impact
Act By
October 5, 2026
Rollout
October 2026

Summary

Starting early October 2026, Windows App will use three new wildcard domains for Windows 365 client traffic. Organizations with network controls must allow outbound HTTPS on port 443 to these domains to avoid connection issues. Review and update firewall, proxy, VPN, DNS, and Secure Web Gateway settings accordingly.

Details

[What and why:]

Beginning in early October 2026, Windows App will begin using three new wildcard fully qualified domain names (FQDNs) for client-side service traffic to Windows 365.

These domains are already included in the cloud-side connectivity requirements. If your organization applies network controls to devices running Windows App, you must allow these endpoints in your client-side network configuration. If the endpoints are not reachable, users may experience sign-in and connection failures.

This is a client-side change for Windows App and is separate from the previous cloud-side domain update. Organizations that have already completed the cloud-side update should still review proxy, firewall, VPN, DNS filtering, and Secure Web Gateway policies that apply to user devices to ensure these endpoints are allowed.

This work is part of a wider Microsoft approach to unify domain requirements.

Required client-side endpoints

*.windows.cloud.microsoft

  • Purpose: General Windows cloud service traffic
  • Port: 443/TCP

*.service.windows.cloud.microsoft

  • Purpose: Service traffic which requires optimization
  • Port: 443/TCP

*.windows.static.microsoft

  • Purpose: Static content, installation, and update assets
  • Port: 443/TCP

[Rollout schedule:]

Windows App will begin using these endpoints in early October 2026.

[Impact to your organization:]

Who is affected

Organizations that:

  • Use Windows App to connect to Windows 365 Cloud PCs.
  • Apply firewall, proxy, VPN, DNS filtering, Secure Web Gateway, or similar network controls to user devices.

Users on unmanaged devices or home networks generally do not need to take action unless network controls block the required endpoints.

[Action required / Recommendations:]

Action required

Before early October 2026:

  • Allow outbound HTTPS traffic on 443/TCP to all three FQDNs in applicable firewall rules, proxy allow lists, VPN configurations, DNS filters, and Secure Web Gateway policies.
  • Review TLS inspection or other traffic interception that could prevent Windows App from reaching Microsoft services. Where permitted by organizational policy, route this traffic directly to Microsoft.
  • If client devices are behind a managed network boundary, engage the team that manages those controls as early as possible, as approval and change-management processes may require additional lead time.
  • Inform your help desk and update internal network and troubleshooting guidance.

Additional information

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.