Forum Discussion

Kazzan's avatar
Nov 12, 2017

Trusted Sites and Local Intranet Assigment for Office 365

Hello, I want to make one unified list of all URL which should be added to Trusted Sites and Local Intranet Zones and after that publish it to TechNet Wiki or Gallery.

 

There are a couple of pages, KB and different service URL for different services and each of them talks about different assignments. Like KB2507767 and Office 365 URL and IP Addresses.

 

Do you have some to add to this list? Do you think it is correct? Thanks for your inputs!

 

Trusted Sites

Local Intranet

  • sts.tenantdomain.url (AD FS)
  • adfs.tenantdomain.url (AD FS)
  • *.office365.com
  • *.microsoftonline.com
  • *.sharepoint.com
  • *.outlook.com
  • *.lync.com
  • autologon.microsoftazuread-sso.com
  • aadg.windows.net.nsatc.net

10 Replies

  • dnsss90's avatar
    dnsss90
    Copper Contributor
    Adding *.sharepoint.com to Local intranet or even Trusted sites is crazy, why would you do that?
  • Richard Rodgers's avatar
    Richard Rodgers
    Copper Contributor

    Hi - I'm very confused about which trusted sites are required to be setup. The list above is helpful but isn't there an official list from Microsoft somewhere?

     

     

    • Kazzan's avatar
      Kazzan
      MVP
      Hi, yes. The official list is in "Office 365 URL and IP Ranges" article. But as i found out, it is incomplete. For example Store for Business is not listed, some Azure services for AAD have listing elsewhere and so on like Teams which has it in "Known Issues".
      • Dustin_Halvorson's avatar
        Dustin_Halvorson
        Steel Contributor

        Kazzan almost two years later, i still feel this is one of the most 'unknown' items of Office 365.  I haven't had one microsoft resource be able to tell me where URLs should be placed.  A lot of 'I thinks', but way too many shrugs of shoulders!

  • And some other within Microsoft Teams were mentioned inside KB.

     

    • https://*.microsoft.com
    • https://*.microsoftonline.com
    • https://*.teams.skype.com
    • https://*.teams.microsoft.com
    • https://*.sfbassets.com
    • https://*.skypeforbusiness.com
  • Hi Petr, just a couple of comments: I would mark these URLs as only required if you use Seamless Single Sign-On (S-SSO): autologon.microsoftazuread-sso.com (S-SSO) aadg.windows.net.nsatc.net (S-SSO) And also that AD FS is not necessarily "tenantdomain", it would be the configured Federation Service URL.
  • NicklasB's avatar
    NicklasB
    Copper Contributor
    Looks like these sites might be missing:
    *.powerbi.com
    *.dynamics.com
    *.microsoftstream.com
    *.onenote.com

Resources