Field guide · Azure Virtual Desktop · Enterprise security

The AVD Allowlist Field Guide

The exclusions, endpoints and security exceptions every Azure Virtual Desktop deployment eventually needs.

Almost every hardened Azure Virtual Desktop deployment eventually reaches the same point: AVD itself is healthy, but a firewall, proxy, EDR platform, secure web gateway, antivirus engine or enterprise security policy prevents part of the service from operating as intended.

Sometimes the failure is obvious: a session host cannot communicate with the service, an application will not install, or an FSLogix profile fails to attach. Other times AVD keeps working but with degraded functionality: RDP Shortpath falls back, profile mounting slows down, or automation becomes unreliable.

This is not one giant allowlist. Start with the mandatory Microsoft platform requirements. Add FSLogix, Nerdio, Windows 365 and vendor-specific exceptions only where those technologies are actually present. For third-party EDR products, investigate the detection first and create the narrowest supported exception.
RequiredRecommendedConditionalTroubleshooting
NET / Network & Firewall

AVD network baseline

Start here. Microsoft publishes the authoritative FQDN and endpoint requirements for AVD. All session-host entries are outbound; opening inbound RDP from the internet is not an AVD requirement.

Azure Virtual Desktop required endpoints

Required

You'll hitRegistration, agent, connection, activation or service-health failures when required AVD destinations are blocked by a firewall or proxy.

FixPermit the complete Microsoft-published AVD endpoint set. Microsoft states that deployments where the required endpoints are blocked aren't supported. Prefer Microsoft-managed service/FQDN tags where they fit, but don't assume a tag replaces every documented dependency.

Selected Azure public cloud endpoints — not the complete allowlist. Use the linked Microsoft documentation for the full session-host and end-user-device requirements, including monitoring and certificate endpoints. Azure Government uses a different endpoint set. Review dependencies such as Microsoft Entra ID, DNS and time services separately.

DestinationPortPurpose
login.microsoftonline.comTCP 443Authentication
*.wvd.microsoft.comTCP 443AVD service / TCP RDP traffic
*.service.windows.cloud.microsoftTCP 443Service traffic
*.windows.cloud.microsoftTCP 443Service traffic
*.windows.static.microsoftTCP 443Service traffic
51.5.0.0/16UDP 3478Relayed RDP connectivity
azkms.core.windows.netTCP 1688Windows activation
mrsglobalsteus2prod.blob.core.windows.netTCP 443Agent / SXS updates

Ref — Microsoft: Required FQDNs and endpoints for AVD

Azure platform addresses

Required

You'll hitProvisioning, health-monitoring and platform-connectivity problems when security appliances, forced tunnelling or local endpoint controls intercept Azure fabric traffic.

FixDon't intercept, proxy or redirect 169.254.169.254 (IMDS) or 168.63.129.16 (Azure platform/WireServer). Microsoft explicitly calls out these addresses for AVD session hosts and Windows 365 Cloud PCs.

Ref — Microsoft: Azure fabric communication IPs

EDR / Antivirus

Endpoint protection

AVD session hosts should remain protected. The objective is not to weaken EDR; it is to identify the exact control blocking legitimate management activity and create the smallest auditable exception.

Each product below links to relevant deployment or exclusion documentation. A general VDI reference is not proof of support for every AVD multi-session or Windows 365 configuration. Customer-only references are identified explicitly; confirm their current instructions in your own tenant. Apply FSLogix exclusions only where FSLogix is deployed, and do not translate exception syntax directly between vendors.

Microsoft Defender / ASR with management automation

Conditional

You'll hitASR controls can interfere with deployment or management workflows that use PowerShell, WMI, DSC, Custom Script Extension or temporary execution locations.

FixKeep the ASR rule enabled. Where the workload vendor documents an exception, use an ASR per-rule exclusion scoped to the relevant session hosts and required path. Don't relax the rule across the tenant.

Ref — Microsoft: ASR rules reference · Nerdio: AVD ASR exclusions

CrowdStrike Falcon

Troubleshooting

You'll hitA confirmed Falcon detection or connectivity problem interrupts deployment or management on a session host or Cloud PC.

FixInvestigate the detection before choosing an exception. Falcon has distinct exclusion mechanisms; do not treat a sensor-visibility exclusion as interchangeable with a detection exception. Scope any supported exception to the affected hosts. Check the Windows sensor deployment guide for image preparation and your Falcon cloud's connectivity requirements.

The public reference identifies exclusion mechanisms, not an AVD or Windows 365 exclusion recipe. The customer documentation could not be independently read during this review; use your regional Falcon console to confirm the current guidance. Do not copy exclusions from another antivirus product without validating their Falcon scope and effect.

Ref — CrowdStrike: Falcon Sensor for Windows (customer login; link/content requires confirmation in your Falcon cloud) · CrowdStrike: Detection and prevention policies (customer login; link/content requires confirmation) · CrowdStrike: exclusion types (public technical reference) · Microsoft: FSLogix exclusions, where deployed

SentinelOne

Troubleshooting

You'll hitA confirmed SentinelOne detection affects a legitimate application or deployment, or a virtual desktop needs agent-specific deployment guidance.

FixUse your tenant's exclusion guidance to choose a narrowly scoped exception for the actual detection. Confirm your Windows version, multi-session support and image lifecycle with SentinelOne before deployment. The public VDI overview is background information, not a current AVD/Windows 365 compatibility matrix or exclusion checklist.

Direct exclusion articles are tenant-specific and require login. In your SentinelOne console, open Help → Online Help and locate Best Practices for Exclusions and Creating a Path Exclusion. Their documented paths are https://<YOUR-SENTINELONE-CONSOLE-HOSTNAME>/docs/en/best-practices-for-exclusions.html and https://<YOUR-SENTINELONE-CONSOLE-HOSTNAME>/docs/en/creating-a-path-exclusion.html. Replace <YOUR-SENTINELONE-CONSOLE-HOSTNAME> with your tenant console hostname; these are URL templates, not public links. Their authenticated contents were not verified in this review.

Ref — SentinelOne: securing VDI (public overview) · SentinelOne: customer KB access (login required) · NinjaOne: documented SentinelOne tenant KB routes · Microsoft: FSLogix exclusions, where deployed

Sophos Intercept X

Troubleshooting

You'll hitA scanning or protection policy affects a confirmed workload, or a cloned endpoint fails to register and receive policy correctly.

FixUse the appropriate Sophos policy to limit scanning exclusions to affected devices. Check UNC paths and wildcard syntax against the Windows exclusions documentation. If you build a reusable image, follow the gold-image process, and permit the Sophos domains and ports required for management and updates.

These are product configuration and VDI references; validate support for your exact AVD or Cloud PC operating system and deployment model.

Ref — Sophos: Windows scanning exclusions · Sophos: gold images and cloned devices · Sophos: domains and ports to allow · Microsoft: FSLogix exclusions, where deployed

Cisco Secure Endpoint

Troubleshooting

You'll hitConnector scanning causes a confirmed application conflict, or reimaging creates duplicate or inconsistent endpoint records.

FixUse Cisco's exclusion-tuning workflow and diagnostics to identify the affected engine and narrowly scoped exception. Review maintained exclusions before adding custom ones. For frequently reimaged desktops, assess identity persistence separately; it is an image-management setting, not a security bypass.

Cisco’s virtual-deployment examples are general VDI guidance. Do not apply non-persistent desktop settings automatically to persistent Cloud PCs or multi-session AVD hosts.

Ref — Cisco KB 213681: configure and identify exclusions · Cisco KB 217557: identity persistence in virtual deployments · Microsoft: FSLogix exclusions, where deployed

Cortex XDR

Troubleshooting

You'll hitA prevention module blocks a confirmed business process, or the agent installation mode does not fit the virtual desktop lifecycle.

FixInvestigate the prevention module involved and confirm the appropriate exception with the documentation or support guidance for your installed version. Review the linked agent virtual-environment guide before image capture and select the installation mode for your desktop lifecycle. Do not apply VMware App Volumes exclusions to AVD or Cloud PCs unless that component is actually part of the deployment.

Select documentation matching your console and agent version. These workflows are not a recommendation to disable prevention across an AVD host pool or Cloud PC estate.

Ref — Palo Alto Networks: virtual environments and desktops · Microsoft: FSLogix exclusions, where deployed

Trend Micro — Apex One and other endpoint products

Troubleshooting

You'll hitScanning interferes with FSLogix container access or a confirmed application workflow.

FixIdentify the installed Trend Micro product first. For Apex One as a Service, review the FSLogix Profile Containers section in its FAQ alongside Microsoft's current prerequisites. Match exclusions to actual container locations and use the policy workflow for your product; Apex One, Worry-Free and Deep Security settings are not interchangeable.

FSLogix exclusions apply only where FSLogix is installed. Do not add them automatically to every Windows 365 Cloud PC.

Ref — Trend Micro: Apex One as a Service FAQ — FSLogix Profile Containers · Trend Micro KB KA-0002520: recommended scan exclusions · Microsoft: current FSLogix prerequisites

FSX / FSLogix

Profile Container security exclusions

FSLogix containers are live virtual disks, not ordinary user files. Microsoft explicitly recommends AV/security exclusions and identifies antivirus processing as a common cause of container corruption.

FSLogix services and drivers

Recommended

You'll hitProfile-mount delays, service crashes, file-access issues, driver blocking or degraded I/O when security tooling interferes with FSLogix services and filter drivers.

FixExclude the Microsoft-documented executables frxsvc.exe, frxccds.exe and drivers frxdrv.sys, frxdrvvt.sys, frxccd.sys.

Ref — Microsoft: FSLogix prerequisites and AV exclusions

FSLogix directories

Recommended

You'll hitHigh CPU, file locking, slow FSLogix responses, logon/logoff latency or profile-load failures.

FixApply the documented directory exclusions, including C:\Program Files\FSLogix\Apps\, C:\ProgramData\FSLogix\ and C:\Users\%username%\AppData\Local\FSLogix\.

Ref — Microsoft: Configure antivirus file and folder exclusions

Cloud Cache

Conditional

You'll hitAV interference with Cloud Cache operations when cache/proxy locations are scanned or locked.

FixIf Cloud Cache is deployed, exclude %ProgramData%\FSLogix\Cache\* and %ProgramData%\FSLogix\Proxy\*, or the actual locations if you've changed the defaults.

Ref — Microsoft: Cloud Cache folder exclusions

VHD/VHDX and SMB container files

Recommended

You'll hitSharing violations, temporary profiles, logoff hangs, file locking or container corruption.

FixApply Microsoft's exclusions for temporary *.VHD/*.VHDX files and the actual SMB/UNC container path, including associated lock/meta/metadata files. Adjust the UNC path to match your Azure Files, ANF or supported SMB design.

Ref — Microsoft: FSLogix AV exclusions · Microsoft: Container corruption

FSLogix registry and mount points

Recommended

You'll hitDLP/AV interference can contribute to stale registry state, temporary profiles, slow logon, sharing violations or logoff hangs.

FixInclude the Microsoft-documented FSLogix registry locations and Profile Mount Points in the security design. Microsoft recommends applying relevant exclusions across endpoint AV, network scanning and DLP layers.

Ref — Microsoft: FSLogix registry and mount-point exclusions

SWG / Secure Web Gateway

Proxy & SSL inspection

A session host can have internet access and still be unable to communicate correctly with a service. Proxies, TLS inspection and secure web gateways need workload-aware handling.

AVD infrastructure traffic

Recommended

You'll hitAdditional latency, agent communication issues or unexpected service behaviour when AVD infrastructure traffic is treated like ordinary web browsing.

FixMicrosoft recommends bypassing proxies for AVD infrastructure, client and session-host agent traffic. Do not use SSL termination for these connections. Session-host AVD components do not support proxies that require authentication. Where a proxy is necessary, follow Microsoft's sizing and geographic-placement guidance and preserve UDP connectivity for RDP Shortpath. Scope this handling to the documented AVD traffic.

Ref — Microsoft: AVD proxy server guidelines

Zscaler Client Connector

Conditional

You'll hitCloud PC sessions freeze or reconnect when Client Connector changes state, or required RDP and platform traffic is steered through an unsuitable path.

FixFollow Zscaler's Windows 365 guide for its predefined Windows 365/AVD IP-based application bypass. It covers RDP gateways and Azure platform communication. Review the configuration on both the Cloud PC and connecting device when both run Client Connector. For AVD, also review Zscaler's Azure deployment guide and confirm the supported client mode for your host design.

The Cloud PC procedure is deployment-specific; it is not a blanket exemption for Microsoft traffic. Confirm current application-profile names and coverage in your installed Client Connector version.

Ref — Zscaler: Client Connector for Windows 365 Cloud PCs · Zscaler: Azure traffic forwarding deployment guide (PDF; includes legacy WVD terminology) · Microsoft: current Cloud PC network requirements

Netskope Client

Conditional

You'll hitAVD service traffic is incorrectly steered, or the client deployment does not account for concurrent users on a shared session host.

FixUse Netskope's AVD steering-bypass procedure for destination locations and, where appropriate, certificate-pinned application exceptions. Review its VDI deployment guide for persistent, non-persistent and multi-user settings. Check current Microsoft endpoint requirements alongside the Netskope configuration. For Windows 365, validate the persistent Cloud PC configuration separately rather than assuming that all AVD multi-user settings apply.

Ref — Netskope: Azure Virtual Desktop steering exceptions · Netskope: VDI deployment, multi-user settings and limitations · Microsoft: Windows 365 network requirements

Other secure web gateways and TLS inspection products

Conditional

You'll hitA proxy, traffic-steering client or TLS inspection policy interrupts required AVD or Cloud PC connectivity.

FixUse Microsoft's AVD proxy guidance and Windows 365 requirements to identify the traffic that needs direct access or special handling. Then use the exact gateway product's supported bypass mechanism. A TLS-decryption exception, a proxy bypass and a routing exception are different controls; choose the one that addresses the observed problem.

This is cross-vendor guidance. There is no single vendor KB for “other SWG”; record the product, version and corresponding vendor procedure before applying an exception.

Ref — Microsoft: AVD proxy and SSL inspection guidance · Microsoft: Windows 365 traffic interception requirements

WinGet / Microsoft Store

Conditional

You'll hitWinGet works on an unrestricted network but fails behind the enterprise proxy/SWG, including certificate-related failures.

FixValidate proxy and TLS-inspection behaviour against Microsoft's current App Installer/WinGet requirements. Prefer a correctly scoped network exception over weakening certificate validation endpoint-wide.

Ref — Microsoft: DesktopAppInstaller policy

UDP / RDP Transport

RDP Shortpath & Multipath

A successful desktop connection does not prove that AVD is using its preferred transport. When UDP isn't available, the service can continue over TCP, turning a firewall issue into a user-experience problem.

TURN-relayed UDP

Recommended

You'll hitDirect Shortpath can't be established and TURN-based UDP relay is unavailable, leaving the session dependent on another transport.

FixFor Azure public cloud, permit outbound connectivity to 51.5.0.0/16 on destination UDP 3478 from both the session-host network and the client network. Microsoft has completed the move from the older shared range to this dedicated AVD/Windows 365 TURN range. Use the separate Microsoft requirements for Azure Government.

Ref — Microsoft: RDP Shortpath

Direct STUN

Recommended

You'll hitThe network prevents direct UDP connectivity, so direct RDP Shortpath can't be established.

FixMicrosoft documents UDP destination ports 1024-65535 with the default dynamic range 49152-65535 for direct STUN. Don't confuse this with TURN's UDP 3478 requirement.

Ref — Microsoft: RDP Shortpath network requirements

RDP Multipath

Recommended

You'll hitA design built only around TCP 443 misses the additional RDP connection methods now available to improve resilience and performance.

FixAccount for TCP-based RDP, UDP via TURN and direct UDP via STUN in the network design, then validate which paths are actually established. On Windows clients, multiple UDP paths require Windows App version 2.0.559.0 or later; the additional redundant TCP functionality requires version 2.0.1069.0 or later. Microsoft recommends the latter or newer with RDP Shortpath as the primary transport. Check the linked documentation for support on other client platforms and availability in your Azure cloud.

Ref — Microsoft: RDP Multipath

NRD / Nerdio Manager

Automation requirements

Nerdio sits on top of the Microsoft platform. It doesn't replace AVD's requirements; it adds automation, deployment and application-management dependencies.

DSC / Custom Script Extension

Conditional

You'll hitNerdio automation fails while normal AVD sessions continue working because security tooling blocks the Azure extension working directories.

FixWhere Nerdio's documented ASR exception applies, use per-rule exclusions for the required locations, including C:\Packages\Plugins\Microsoft.Compute.CustomScriptExtension\*\Downloads\* and C:\Packages\Plugins\Microsoft.PowerShell.DSC\*\DSCWork\*. Keep the underlying ASR rule enabled.

Ref — Nerdio: Attack Surface Reduction — AVD Exclusions

Unified Application Management

Conditional

You'll hitUAM deployment is blocked by endpoint protection while other Nerdio functions continue working.

FixFor Nerdio Manager for Enterprise, confirm the blocked operation against the detection and Nerdio's guidance. Its documented UAM paths are C:\Windows\Temp\NME-SHELL-FILE-CACHE\* for most UAM packages and C:\Windows\Temp\NMWLogs\* for UAM packages deployed on Intune devices. Apply the relevant ASR per-rule exclusions only to devices running these packages, keep the affected rules enabled, and verify the actual paths for your deployment.

Ref — Nerdio: UAM ASR exclusions

Nerdio outbound access

Required when used

You'll hitDSC, scripted actions, agent deployment, FSLogix installation or application automation fails because the host can reach AVD but not the resources required by Nerdio or the script itself.

FixApply Nerdio's current outbound requirements in addition to Microsoft's AVD requirements. Remember that individual scripted actions can introduce their own vendor/CDN dependencies.

Ref — Nerdio: Required outbound internet access

W365 / Windows 365

Cloud PC requirements

AVD and Windows 365 share Windows cloud infrastructure, but don't treat their network requirements as identical. Windows 365 has service, Intune, RDP and deployment-model dependencies of its own.

Windows 365 networking

Required when used

You'll hitCloud PC provisioning, management, health or connectivity failures despite the AVD firewall configuration appearing healthy.

FixApply Microsoft's current Windows 365 network requirements separately. For ANC deployments, required endpoints must be reachable from the VNet and Cloud PCs. For Microsoft Hosted Network, device-level VPN/SWG/proxy controls must still permit required Windows 365 endpoints and RDP traffic.

Ref — Microsoft: Windows 365 network requirements

Traffic interception

Recommended

You'll hitANC checks, provisioning or RDP performance issues when SSL decryption, deep packet inspection or other interception technologies interfere with required Cloud PC connectivity.

FixFollow Microsoft's current Windows 365 traffic-interception and RDP-optimization guidance. Treat service/RDP traffic differently from ordinary user web traffic where Microsoft requires or recommends it.

Ref — Microsoft: Windows 365 traffic interception requirements

VPN / ZTNA

Remote access clients on shared hosts

This is an architecture check rather than a universal allowlist. A VPN agent designed for one interactive user might not be appropriate for a Windows 11 Enterprise multi-session host.

Traditional VPN clients on multi-session AVD

Architecture

You'll hitA VPN or network agent behaves unpredictably or isn't supported once multiple users share the same Windows host.

FixVerify the vendor's explicit Windows multi-session support before putting the client into the image. Where full-device VPN isn't appropriate, evaluate vendor-supported ZTNA/private-access or application-level access models. Don't try to solve an unsupported architecture with progressively wider exclusions.

Ref — Netskope: VDI deployment models and limitations · Zscaler: Azure traffic forwarding deployment guide

VAL / Validation

Prove the allowlist works

The change isn't complete when the firewall rule is approved. Validate endpoint access, transport, FSLogix behaviour and security policy application from the workload itself.

Azure Virtual Desktop Agent URL Tool

Recommended

You'll hitThe firewall team says the required destinations are allowed, while the session host still can't reach one or more AVD endpoints.

FixRun .\WVDAgentUrlTool.exe from the installed RDAgent directory. It lists accessible and inaccessible required destinations. Microsoft notes that the tool doesn't prove the complete wildcard entries are allowed, so a successful test doesn't replace correct wildcard configuration.

Ref — Microsoft: Check access to required AVD endpoints

Validate the actual RDP transport

Recommended

You'll hitUsers can connect, but latency or responsiveness isn't where expected.

FixDon't stop at “can the user connect?” Determine whether the session is using TCP, TURN-relayed UDP or direct STUN/Shortpath connectivity. A connected desktop and an optimised AVD connection are not the same thing.

Ref — Microsoft: RDP Shortpath · Microsoft: RDP Multipath

Validate FSLogix after policy deployment

Recommended

You'll hitExclusions are supposedly configured but profile attachment remains slow or inconsistent.

FixConfirm the security policy actually reached the session host and matches the real cache, profile-container and SMB paths. Review FSLogix logs, container attachment, service health and storage performance. Microsoft explicitly recommends validating exclusions after policy deployment.

Ref — Microsoft: FSLogix prerequisites