Firewall Whitelisting for Azure DevOps (South India) – dev.azure.com via Front Door/CDN

Hamja Dhuka 0 Reputation points
2025-08-26T11:29:08.7033333+00:00

Dear Microsoft Azure Team,

We are facing challenges while allowing Azure DevOps (dev.azure.com) through our on-premises firewall.

Our Azure DevOps organization is located in the South India region. We have already allowed the domain dev.azure.com, but we are still encountering connectivity issues. From our firewall logs, we observed that requests are coming via Azure Front Door/CDN with dynamic IPs that change frequently (weekly updates).

Our concern is:

Do we have the possibility to whitelist a single domain or fixed IP range for South India DevOps traffic, instead of allowing multiple dynamic IP ranges for CDN/Front Door?

If not, what is the recommended best practice to securely allow DevOps traffic from South India region to our on-premises servers, while minimizing firewall changes?

We would appreciate your guidance on the most efficient way to configure firewall rules for Azure DevOps connectivity.

Regards,

Hamja D

ACG World

Azure DevOps
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. JimmySalian-2011 43,271 Reputation points
    2025-08-28T09:33:30.37+00:00

    Hi Hamja,

    Can you try with wildcard as it will cover all other dependant domain names and you should not face this issue again, can you share this with your FW / Network team?

    The new Domain URL https://*.dev.azure.com

    https://devblogs.microsoft.com/devops/cdn-domain-url-change-for-agents-in-pipelines/#update-the-firewall-allow-list

    Hope this helps.

    JS

    ==

    Please Accept the answer if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.