SOLVED

Device Management in Teams, URLs and IP address ranges

%3CLINGO-SUB%20id%3D%22lingo-sub-1489484%22%20slang%3D%22en-US%22%3EDevice%20Management%20in%20Teams%2C%20URLs%20and%20IP%20address%20ranges%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1489484%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20any%20documentation%20on%20the%20URLs%20used%20with%20a%20Teams%20desk%20phone%3F%3C%2FP%3E%3CP%3ESpecifically%20related%20to%20device%20management.%3C%2FP%3E%3CP%3E(Similar%20to%26nbsp%3BOffice%20365%20URLs%20and%20IP%20address%20ranges)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECapturing%20the%20traffic%20from%20a%20phone%2C%20from%20the%20point%20of%20it%20booting%2C%20to%20it%20pulling%20down%20new%20firmware%20it%20appears%20to%20reach%20out%20to%20the%20following%20largely%20in%20the%20order%20shown%20below%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CTABLE%20width%3D%22330%22%3E%3CTBODY%3E%3CTR%3E%3CTD%20width%3D%22330%22%3Epool.ntp.org%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E%3CMANUFACTURER%20url.%3D%22%22%20eg%3D%22%22%20g.cn%3D%22%22%3E%3C%2FMANUFACTURER%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E%3CA%20href%3D%22http%3A%2F%2Fwww.google.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ewww.google.com%3C%2FA%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E2.android.pool.ntp.org%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3Elogin.windows.net%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E*.teams.microsoft.com%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3Eoutlook.office.com%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E%3CSTRONG%3Ein.appcenter.ms%3C%2FSTRONG%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%3E%3CSTRONG%3Eteamsdevicemgmtsvcprod.blob.core.windows.net%26nbsp%3B%3C%2FSTRONG%3E%3C%2FTD%3E%3C%2FTR%3E%3C%2FTBODY%3E%3C%2FTABLE%3E%3CP%3ESo%20overall%20everything%20up%20to%20the%20last%20two%20URLs%20are%20documented%20either%20by%20the%20manufacturer%20or%20from%26nbsp%3BOffice%20365%20URLs%20and%20IP%20address%20ranges.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20stumble%20upon%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.msxfaq.de%2Fteams%2Ftelefon%2Fteams_phone_management.htm%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.msxfaq.de%2Fteams%2Ftelefon%2Fteams_phone_management.htm%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EReason%20for%20asking%20is%20from%20my%20home%20network%2C%20phone%20updates%20work%20without%20a%20hitch%3C%2FP%3E%3CP%3EHowever%20from%20the%20corporate%20network%20with%26nbsp%3BPalo%20Alto%20Firewalls%20the%20phones%20aren't%20updating%3C%2FP%3E%3CP%3EI%20need%20to%20understand%20the%20process%20and%20work%20with%20the%20network%20team%20to%20fix%20this%20etc.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20advice%20welcome%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1489484%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1494795%22%20slang%3D%22en-US%22%3ERe%3A%20Device%20Management%20in%20Teams%2C%20URLs%20and%20IP%20address%20ranges%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1494795%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20should%20only%20have%20to%20open%20for%20the%20URLs%20and%20addresses%20mentioned%20in%20the%20Office%20365%20URLs%20and%20IP%20documentation.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Furls-and-ip-address-ranges%23skype-for-business-online-and-microsoft-teams%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Foffice365%2Fenterprise%2Furls-and-ip-address-ranges%23skype-for-business-online-and-microsoft-teams%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOther%20addresses%20it%20tries%20to%20connect%20to%20is%20since%20it%20is%20running%20Android%20and%20Android%20will%20try%20to%20connect%20to%20those%20addresses.%20NTP%20settings%20you%20can%20change%20in%20the%20phone%20settings%20so%20you%20use%20something%20else%20than%20ntp.org%20if%20you%20want%20to.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EUpdates%20should%20be%20downloaded%20from%20Microsoft%20servers%20after%20you%20have%20approved%20them%20in%20Teams%20Admin%20Center%20or%20when%20you%20trigger%20a%20phone%20to%20update%20firmware%20or%20software%20from%20TAC.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1500149%22%20slang%3D%22en-US%22%3ERe%3A%20Device%20Management%20in%20Teams%2C%20URLs%20and%20IP%20address%20ranges%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1500149%22%20slang%3D%22en-US%22%3E%3CP%3Ethanks%20for%20the%20reply%3C%2FP%3E%3CP%3Ehowever%20the%20url%26nbsp%3B%3C%2FP%3E%3CPRE%3Ehttps%3A%2F%2Fteamsdevicemgmtsvcprod.blob.core.windows.net%3C%2FPRE%3E%3CP%3Eappears%20to%20be%20where%20the%20phone%20firmware%20is%20actually%20downloaded%20from%3C%2FP%3E%3CP%3Ei%20noted%20this%20in%20my%20network%20capture%20(looking%20at%20dns%20queries)%20and%20the%20article%20I%20linked%20to%20also%20noted%20this%20in%20the%20phone%20logs%20Plus%20actually%20pulled%20firmware%20from%20the%20url.%3C%2FP%3E%3CP%3Ei%20can%E2%80%99t%20find%20mention%20of%20this%20in%20any%20ms%20documentation.%20However%20you%20are%20welcome%20for%20you%20to%20prove%20me%20a%20liar!%3CBR%20%2F%3Eso%20you%20can%20see%20why%20I%20am%20a%20bit%20worried.%20If%20this%20is%20true%2C%20what%20else%20might%20there%20be.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Is there any documentation on the URLs used with a Teams desk phone?

Specifically related to device management.

(Similar to Office 365 URLs and IP address ranges)

 

Capturing the traffic from a phone, from the point of it booting, to it pulling down new firmware it appears to reach out to the following largely in the order shown below

 

pool.ntp.org
<manufacturer URL. Eg g.cn>
www.google.com
2.android.pool.ntp.org
login.windows.net
*.teams.microsoft.com
outlook.office.com
in.appcenter.ms
teamsdevicemgmtsvcprod.blob.core.windows.net 

So overall everything up to the last two URLs are documented either by the manufacturer or from Office 365 URLs and IP address ranges.

 

I did stumble upon

https://www.msxfaq.de/teams/telefon/teams_phone_management.htm

 

Reason for asking is from my home network, phone updates work without a hitch

However from the corporate network with Palo Alto Firewalls the phones aren't updating

I need to understand the process and work with the network team to fix this etc.

 

Any advice welcome

 

2 Replies
Best Response confirmed by ThereseSolimeno (Microsoft)
Solution

You should only have to open for the URLs and addresses mentioned in the Office 365 URLs and IP documentation. https://docs.microsoft.com/en-us/office365/enterprise/urls-and-ip-address-ranges#skype-for-business-...

 

Other addresses it tries to connect to is since it is running Android and Android will try to connect to those addresses. NTP settings you can change in the phone settings so you use something else than ntp.org if you want to.

 

Updates should be downloaded from Microsoft servers after you have approved them in Teams Admin Center or when you trigger a phone to update firmware or software from TAC.

thanks for the reply

however the url 

https://teamsdevicemgmtsvcprod.blob.core.windows.net

appears to be where the phone firmware is actually downloaded from

i noted this in my network capture (looking at dns queries) and the article I linked to also noted this in the phone logs Plus actually pulled firmware from the url.

i can’t find mention of this in any ms documentation. However you are welcome for you to prove me a liar!
so you can see why I am a bit worried. If this is true, what else might there be.