Forum Discussion

jilltre80000's avatar
jilltre80000
Copper Contributor
Aug 20, 2026
Solved

SharePoint Migration Tool issue

Got an issue that one of the endpoints for SPMT is not working or part of the firewall. When they try to add it, it doesn't see it as valid:

https://api.office.com

 

I've seen various comments that this api.office.com has been deprecated, but it is still listed in the KB article as needing to be opened in the firewall. 

 

Can I get confirmation that this is still a needed endpoint?

https://learn.microsoft.com/en-us/sharepointmigration/spmt-prerequisites?utm_source=openai

 

Thanks!

  • Microsoft’s current SPMT prerequisites still list the endpoint shown in your firewall rule as required for Microsoft 365 content-move and validation APIs. Therefore, its rejection cannot be treated as proof that SPMT no longer needs it, even if another Office API using that hostname was deprecated. Allow that fully qualified domain name over TCP 443 from the computer running SPMT, together with the other documented SPMT endpoints, and use DNS-based rules rather than pinning IP addresses. If your security product rejects the entry as syntactically invalid, enter only the hostname in an FQDN object or use its documented URL-category format; the scheme may be what that field refuses. After the rule is applied, test DNS resolution and an outbound TLS connection from the SPMT host, then rerun the migration scan. If policy forbids that endpoint, raise the conflict with Microsoft support and your firewall vendor.

1 Reply

  • Microsoft’s current SPMT prerequisites still list the endpoint shown in your firewall rule as required for Microsoft 365 content-move and validation APIs. Therefore, its rejection cannot be treated as proof that SPMT no longer needs it, even if another Office API using that hostname was deprecated. Allow that fully qualified domain name over TCP 443 from the computer running SPMT, together with the other documented SPMT endpoints, and use DNS-based rules rather than pinning IP addresses. If your security product rejects the entry as syntactically invalid, enter only the hostname in an FQDN object or use its documented URL-category format; the scheme may be what that field refuses. After the rule is applied, test DNS resolution and an outbound TLS connection from the SPMT host, then rerun the migration scan. If policy forbids that endpoint, raise the conflict with Microsoft support and your firewall vendor.