An Azure internet of things security solution including hardware, operating system, and cloud components.
Hi David Boross ,
Thank you for the detailed information.
Based on the Azure Sphere networking requirements, Azure Sphere services rely on the published FQDN endpoints documented in the official networking guidance, including update, security, provisioning, and connectivity validation services. Some of these services are delivered through Microsoft's content delivery infrastructure and may resolve to dynamically changing CDN endpoints, including Akamai-hosted addresses.
Regarding your questions:
1.** CDN Routing and Firewall **Configuration Azure Sphere networking requirements are based on allowing the documented FQDNs rather than permitting a fixed set of IP addresses. Since CDN-backed services can use dynamic DNS resolution and IP rotation, Microsoft does not publish a static IP allow-list for Azure Sphere service endpoints. Firewall implementations that rely solely on IP-based rules may encounter issues when CDN address mappings change.
2.** DNS Resolution **Consistency The recommended approach is to ensure that firewall policy evaluation follows DNS-based/FQDN-based allow-listing for the documented Azure Sphere endpoints. Because CDN providers may return different IP addresses depending on resolver location and network conditions, firewalls should support appropriate FQDN tracking and DNS resolution handling for the allowed domains.
3.** Static IP Ranges / Service **Tags At this time, Azure Sphere documentation does not provide dedicated Azure Service Tags, static IP ranges, or ASN-based allow lists for Azure Sphere service communication. The supported method is allowing the documented domains and required ports.
4.** TLS/SSL **Inspection Azure Sphere devices use certificate validation and secure TLS communications with Azure Sphere services. SSL/TLS interception, HTTPS inspection, certificate substitution, or deep packet inspection that modifies the TLS session may interfere with device connectivity and should be excluded for the Azure Sphere service endpoints where applicable.
To further investigate the observed blocking behavior, it would be helpful if the customer could provide:
- Firewall vendor and model
- Example blocked FQDNs and corresponding resolved IP addresses
- Firewall logs showing the denied connections
- Details of any TLS inspection, SSL proxy, or outbound security inspection policies in place
This information will help determine whether the issue is related to FQDN tracking, DNS resolution differences between the firewall and device, or TLS inspection behavior.