Hello @Denny GLADWIN , No this list won’t work. Those 150.171.x.x ranges are the inbound addresses for reaching Azure DevOps itself, and the page they come from is explicit that they don’t cover hosted agents. From Allowed IP addresses and domain URLs: “The Service Tag or previously mentioned inbound IP addresses don’t apply to Microsoft Hosted agents. Customers are still required to allow the entire geography for the Microsoft Hosted agents.”
On your three questions.
There isn’t a fixed list. The ranges sit in a weekly JSON file Microsoft publishes, under AzureCloud.<region>, documented on Microsoft-hosted agents.
It changes every week, and only the current file is downloadable, so you have to fetch it yourself and keep your own copies if you want history. New ranges take effect the week after they appear. If pipelines suddenly start failing, that file is the first thing to re-check.
On failover, yes. Your agent isn’t pinned to your organization’s region: “While your agent might run in the same region as your organization, it isn’t guaranteed to do so.“ You need every region in your geography, not just your own.
Worth mentioning that this is a lot of surface area to allowlist and it moves every week. Microsoft’s own suggestion if that’s a problem: “If allowing the entire geography is a concern, we recommend using the Microsoft Managed DevOps Pools. Alternatively, you can also use Azure Virtual Machine Scale Set agents.” Both put your agents on IPs you control, which is usually what the firewall team actually wants.
Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.