> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Using Iru on Enterprise Networks

> Configure enterprise network settings for Iru Endpoint. Allow required domains, ports, and IP ranges through firewalls and proxies for MDM communication.

Some organizations may create **Enrollment Only** networks or put **Proxies** in place to limit access to the public internet. In these situations, it is important to ensure that your Apple, Windows, and Android devices can communicate with platform services and Iru to complete enrollment and management tasks.

<Note>
  When creating firewall rules for these ports, **outbound** traffic will need to be allowed.
</Note>

## Global Web App Access

Regardless of region, all Iru tenants access the web app through a single global domain: `subdomain.iru.com`.

<Note>
  The region-specific tables below also list `subdomain.kandji.io` and `subdomain.eu.kandji.io` as web app access domains. These are legacy hostnames that route to the same Iru service.
</Note>

Your data remains isolated within its assigned region. When the app loads, a lookup is performed against a globally available service (the Identity Service) to determine your tenant's region. All subsequent API calls are then routed to region-specific load balancers accordingly.

For details on signing in and accessing your tenant, see [Getting Started](/en/endpoint/getting-started/getting-started).

## Required Domains & Ports

### Domains Shared Across All Regions

The following domains are required for all tenants regardless of region:

| <Icon icon="globe" size={14} /> Domain | <Icon icon="plug" size={14} /> Ports | <Icon icon="shield" size={14} /> Protocol | <Icon icon="desktop" size={14} /> OS                                                                                                                            | <Icon icon="circle-info" size={14} /> Description                                      |
| -------------------------------------- | ------------------------------------ | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- |
| `browser-intake-datadoghq.com`         | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for release management and platform monitoring                                    |
| `events.launchdarkly.com`              | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for release management and platform monitoring                                    |
| `updater.iru.com`                      | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for Iru Access downloads and updates                                              |
| `*.c.lencr.org`                        | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for Let's Encrypt certificate validation via Certificate Revocation Lists (CRLs). |

### Region-Specific Domains

<Tabs>
  <Tab title="US Region" icon="earth-americas" iconType="regular">
    ### US-Hosted Region Domains

    | <Icon icon="globe" size={14} /> Domain                                                                                                                                                                                                                                                                                                                                       | <Icon icon="plug" size={14} /> Ports | <Icon icon="shield" size={14} /> Protocol | <Icon icon="desktop" size={14} /> OS                                                                                                                            | <Icon icon="circle-info" size={14} /> Description                                                                                                                                                                  |
    | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------ | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`UUID.web-api.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`UUID.devices.us-1.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`UUID.devices.iru.com`</span>                                                                                                     | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for MDM Check-In and Iru Agent communication. Replace UUID with your tenant's value. See [Determine your unique device domains](#determine-your-unique-device-domains) for how to find your UUID and domains. |
    | `kandji-prd.s3.amazonaws.com`                                                                                                                                                                                                                                                                                                                                                | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> macOS                                                                                                         | Used by macOS devices to download the Iru Agent & Custom Apps uploaded to your Iru tenant                                                                                                                          |
    | `iru-prd-managed-library-items.s3.amazonaws.com`                                                                                                                                                                                                                                                                                                                             | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> macOS                                                                                                         | Used by macOS devices to download Auto Apps                                                                                                                                                                        |
    | `managed-library.kandji.io`                                                                                                                                                                                                                                                                                                                                                  | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> macOS                                                                                                         | Used by macOS devices to download Auto Apps                                                                                                                                                                        |
    | `subdomain.web-api.kandji.io`                                                                                                                                                                                                                                                                                                                                                | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used to download Mobile Device Management (MDM) Enrollment Profile                                                                                                                                                 |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.iru.com`</span>                                                                                                                                                                                                       | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used to access the Iru web app                                                                                                                                                                                     |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.gateway.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.gateway.iru.com`</span>                                                                                                                                                                                       | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used by Iru web app to access Iru APIs.                                                                                                                                                                            |
    | `*.iot.kandji.io`                                                                                                                                                                                                                                                                                                                                                            | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for device telemetry communications                                                                                                                                                                           |
    | `windows-agent.kandji.io`                                                                                                                                                                                                                                                                                                                                                    | 443                                  | TCP                                       | <Icon icon="microsoft" size={14} iconType="brands" /> Windows                                                                                                   | Used to install and upgrade the Iru Agent on Windows                                                                                                                                                               |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.connect.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.devices.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.gateway.iru.com`</span> | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Access point for the Iru Identity API service serving US tenants. Within the Iru web app, it is used universally across all tenants, independent of Iru Workforce Identity licensing                               |
  </Tab>

  <Tab title="EU Region" icon="globe" iconType="regular">
    ### EU-Hosted Region Domains

    | <Icon icon="globe" size={14} /> Domain                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | <Icon icon="plug" size={14} /> Ports | <Icon icon="shield" size={14} /> Protocol | <Icon icon="desktop" size={14} /> OS                                                                                                                            | <Icon icon="circle-info" size={14} /> Description                                                                                                                                                                                                                                                                                                       |
    | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------ | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`UUID.web-api.eu.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`UUID.devices.eu.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`UUID.devices.eu.iru.com`</span>                                                                                                                                                                                                                                                                                               | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for MDM Check-In and Iru Agent communication. Replace UUID with your tenant's value. See [Determine your unique device domains](#determine-your-unique-device-domains) for how to find your UUID and domains.                                                                                                                                      |
    | `kandji-prd-eu.s3.amazonaws.com`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> macOS                                                                                                         | Used by macOS devices to download the Iru Agent & Custom Apps uploaded to your Iru tenant                                                                                                                                                                                                                                                               |
    | `iru-prd-eu-managed-library-items.s3.amazonaws.com`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> macOS                                                                                                         | Used by macOS devices to download Auto Apps                                                                                                                                                                                                                                                                                                             |
    | `managed-library.eu.kandji.io`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> macOS                                                                                                         | Used by macOS devices to download Auto Apps                                                                                                                                                                                                                                                                                                             |
    | `subdomain.web-api.eu.kandji.io`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used to download Mobile Device Management (MDM) Enrollment Profile                                                                                                                                                                                                                                                                                      |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.eu.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.iru.com`</span>                                                                                                                                                                                                                                                                                                                                                                                                  | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used to access the Iru web app                                                                                                                                                                                                                                                                                                                          |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.gateway.eu.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.gateway.eu.iru.com`</span>                                                                                                                                                                                                                                                                                                                                                                               | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used by Iru web app to access Iru APIs.                                                                                                                                                                                                                                                                                                                 |
    | `*.iot.eu.kandji.io`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Used for device telemetry communications                                                                                                                                                                                                                                                                                                                |
    | `windows-agent.eu.kandji.io`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | 443                                  | TCP                                       | <Icon icon="microsoft" size={14} iconType="brands" /> Windows                                                                                                   | Used to install and upgrade the Iru Agent on Windows                                                                                                                                                                                                                                                                                                    |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.eu.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.connect.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.connect.eu.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.devices.eu.iru.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`subdomain.id.gateway.eu.iru.com`</span> | 443                                  | TCP                                       | <Icon icon="apple" size={14} iconType="brands" /> <Icon icon="microsoft" size={14} iconType="brands" /> <Icon icon="android" size={14} iconType="brands" /> All | Access point for the Iru Identity API service serving EU tenants. Within the Iru web app, it is used universally across all tenants, independent of Iru Workforce Identity licensing.<br /><br />The US id domain is used as a global lookup service to know which region your tenant belongs to, and forward all further traffic to the EU api region. |
  </Tab>
</Tabs>

## AD CS Integration Network Requirements

If you use the Active Directory Certificate Services integration, allow these network paths for AD CS Connector setup and certificate request flow. For full integration context, see [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview).

<Note>
  The **updated** AD CS Connector uses Iru sign-in and **registration URL** approval in the Iru Endpoint web app. It does **not** use Auth0. Use the **Updated AD CS Connector** table for standard allowlists (Iru tenant, Iru tenant API, Iru Identity, `adcsconn`, and internal AD CS CA traffic as listed). Include your Iru web app and any additional Iru Identity destinations from elsewhere in this article where those rows apply to your tenant. If any Windows servers still run the **legacy** connector during migration, also allow the destinations in the **Legacy AD CS Connector** table until those hosts are upgraded and the legacy connector is removed from Iru Endpoint.
</Note>

### Updated AD CS Connector

| Source          | Destination                                    | Destination domains                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Port                    | Protocol | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| --------------- | ---------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AD CS Connector | Iru tenant                                     | <span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.iru.com`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.eu.kandji.io`</span>                                                                                                                                                                                                                                                                                                                                                                                        | 443                     | TCP      | Used during initial connector setup for Iru sign-in and **registration URL** approval in the Iru Endpoint web app                                                                                                                                                                                                                                                                                                                                          |
| AD CS Connector | Iru tenant API                                 | <span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.gateway.iru.com`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.gateway.eu.iru.com`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.gateway.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.gateway.eu.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.clients.us-1.kandji.io`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.clients.eu.kandji.io`</span> | 443                     | TCP      | Used for API communication between the AD CS Connector and your tenant.<br /><br />Replace **subdomain** with your tenant subdomain. **Gateway** hostnames match [Region-specific domains](#region-specific-domains).<br /><br />**Clients** rows are tenant-scoped client API hosts: `subdomain.clients.us-1.kandji.io` for **US Region** tenants and `subdomain.clients.eu.kandji.io` for **EU Region** tenants (same regional split as the tabs above). |
| AD CS Connector | Iru Identity                                   | <span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.id.iru.com`</span><span style={{ display: 'block', marginBottom: '3px', whiteSpace: 'nowrap' }}>`subdomain.id.eu.iru.com`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | 443                     | TCP      | Used for Iru Identity during sign-in and token flows for the updated connector                                                                                                                                                                                                                                                                                                                                                                             |
| AD CS Connector | AD CS connector service                        | <span style={{ whiteSpace: 'nowrap' }}>`adcsconn.kandji.io`<br />`adcsconn.eu.kandji.io`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | 443                     | TCP      | WebSocket over TCP. Used to facilitate certificate requests between the AD CS Connector and the customer tenant                                                                                                                                                                                                                                                                                                                                            |
| AD CS Connector | Windows AD CS CA server(s) in your environment | Internal AD CS CA server FQDN(s)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | 135 + dynamic RPC range | TCP      | Microsoft DCE/RPC between the connector and issuing CAs when processing certificate requests                                                                                                                                                                                                                                                                                                                                                               |

Microsoft RPC is not a single fixed high port. Allow **TCP 135** (RPC Endpoint Mapper) to each issuing CA FQDN, and the **Windows dynamic RPC port range** each CA host uses, often the range shown as **RPC Dynamic Ports** in Windows Defender Firewall with Advanced Security on the certificate server. Confirm the range on every issuing CA and mirror it in your firewall or proxy rules. For background, see [Configure RPC dynamic port allocation with firewalls](https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/configure-rpc-dynamic-port-allocation-with-firewalls) on Microsoft Learn.

### Legacy AD CS Connector (migration only)

Allow these destinations **only** while at least one Windows server still runs the **legacy** connector (Auth0-based WebView sign-in during setup). When every connector uses the **updated** flow from Iru, remove these allowlist rows.

| Source          | Destination | Destination domains                                                                     | Port | Protocol | Description                                                                                                       |
| --------------- | ----------- | --------------------------------------------------------------------------------------- | ---- | -------- | ----------------------------------------------------------------------------------------------------------------- |
| AD CS Connector | Auth0       | <span style={{ whiteSpace: 'nowrap' }}>`*.auth0.com`</span>                             | 443  | TCP      | **Legacy connector only.** Multiple subdomains used for initial WebView authentication during connector setup     |
| AD CS Connector | Auth0       | <span style={{ whiteSpace: 'nowrap' }}>`auth.kandji.io`<br />`auth.eu.kandji.io`</span> | 443  | TCP      | **Legacy connector only.** Used when authenticating the AD CS Connector during setup and WebSocket initialization |

## Determine Your Unique Device Domains

Your unique device domains are used by enrolled devices to communicate with Iru via the MDM protocol and the Iru Agent.

**US region examples:**

* `UUID.web-api.kandji.io`
* `UUID.devices.us-1.kandji.io`
* `UUID.devices.iru.com`

**EU region examples:**

* `UUID.web-api.eu.kandji.io`
* `UUID.devices.eu.kandji.io`
* `UUID.devices.eu.iru.com`

The UUID is unique to your tenant. You can view your tenant's domains by logging into your tenant and following these steps:

<Steps>
  <Step title="Open Organization">
    In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Organization**.
  </Step>

  <Step title="View Device Domains">
    Under **Endpoint**, you will see the **Device Domains** panel. These domains are used by devices for MDM and Agent communication.
  </Step>
</Steps>

### Find Device Domain on a Mac

To determine the specific domain being used by an individual Mac computer, run the following command in Terminal:

```bash Terminal icon="terminal" theme={null}
system_profiler SPConfigurationProfileDataType | awk -v FS='(https://|/mdm)' '/CheckInURL/ {print $2}'
```

## SSL/TLS Inspection

The macOS Iru Agent leverages a common best practice of certificate pinning to ensure that it will only communicate with trusted servers and prevent its traffic from being intercepted and inspected (MITM attack prevention). This may pose a challenge if your network or proxy administrator is decrypting all SSL/TLS traffic by default. Please ask your network administrator to exempt your tenant's device domains from inspection.

<Warning>
  Please note that even if you deploy your content filter's CA as a trusted root CA to your macOS devices, SSL/TLS inspection will still cause the Iru Agent to not communicate with Iru.
</Warning>

## Platform-Specific Network Requirements

<Tabs>
  <Tab title="Apple" icon="apple" iconType="brands">
    ### Apple Required Hosts & Ports

    Apple devices require access to various Apple services for proper enrollment and management. For comprehensive Apple network requirements, refer to Apple's official guide: [Configure devices to work with APNs](https://support.apple.com/guide/deployment/configure-devices-to-work-with-apns-dep2de55389a/1/web/1.0).

    | <Icon icon="globe" size={14} /> Destination Host | <Icon icon="plug" size={14} /> Ports | <Icon icon="circle-info" size={14} /> Purpose                           |
    | ------------------------------------------------ | ------------------------------------ | ----------------------------------------------------------------------- |
    | Apple network (`17.0.0.0/8`)                     | TCP/443                              | Device activation and fallback if devices can't reach APNs on port 5223 |
    | Apple network (`17.0.0.0/8`)                     | TCP/5223                             | Primary communication with Apple Push Notification service (APNs)       |
    | Apple network (`17.0.0.0/8`)                     | TCP/443 or 2197                      | Send notifications from device management service to APNs               |
  </Tab>

  <Tab title="Windows" icon="microsoft" iconType="brands">
    ### Windows Required Hosts & Ports

    Windows devices require access to Microsoft services for proper enrollment and management:

    | <Icon icon="globe" size={14} /> Destination Host                                                                                                                                                                                                                                                                                                 | <Icon icon="plug" size={14} /> Ports | <Icon icon="circle-info" size={14} /> Purpose                                                                                                                                                                                                                             |
    | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`*.notify.windows.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`*.wns.windows.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`login.microsoftonline.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`login.live.com`</span> | TCP/443                              | Required for Windows Push Notification Services (WNS). For detailed configuration requirements, see [Microsoft's WNS firewall allowlist documentation](https://learn.microsoft.com/en-us/windows/apps/develop/notifications/push-notifications/firewall-allowlist-config) |

    <Note>
      Additional URLs may be required for Windows-specific features to function properly. For a comprehensive list of Windows endpoints, refer to [Microsoft's Windows 11 endpoints documentation for non-enterprise editions](https://learn.microsoft.com/en-us/windows/privacy/windows-11-endpoints-non-enterprise-editions) or [Microsoft's Windows 11 endpoints documentation for enterprise editions](https://learn.microsoft.com/en-us/windows/privacy/manage-windows-11-endpoints).
    </Note>
  </Tab>

  <Tab title="Android" icon="android" iconType="brands">
    ### Android Required Hosts & Ports

    Android devices require access to Google services for proper enrollment and management. For comprehensive Android network requirements, refer to [Google's Android Enterprise network requirements](https://support.google.com/work/android/answer/10513641?hl=en).

    | <Icon icon="globe" size={14} /> Destination Host                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | <Icon icon="plug" size={14} /> Ports | <Icon icon="circle-info" size={14} /> Purpose                             |
    | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------ | ------------------------------------------------------------------------- |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`play.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`android.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`google-analytics.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`googleusercontent.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`*.gstatic.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`*.gvt1.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`*.ggpht.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`dl.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`dl-ssl.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`android.apis.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`*.gvt2.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`*.gvt3.com`</span>                                                                                     | TCP/443<br />TCP, UDP/5228-5230      | Google Play and updates, app downloads, and Play Store APIs               |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`*.googleapis.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`m.google.com`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | TCP/443                              | EMM/Google APIs/PlayStore APIs/Android Management APIs                    |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`accounts.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`accounts.google.[country]`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | TCP/443                              | Authentication (use your local top-level domain for \[country])           |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`gcm-http.googleapis.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`gcm-xmpp.googleapis.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`android.googleapis.com`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | TCP/443, 5228-5230                   | Google Cloud Messaging for EMM Console ↔ DPC communication                |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`fcm.googleapis.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`fcm-xmpp.googleapis.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`firebaseinstallations.googleapis.com`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | TCP/443, 5228-5230                   | Firebase Cloud Messaging for Find Hub and EMM Console ↔ DPC communication |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`connectivitycheck.android.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`connectivitycheck.gstatic.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`www.google.com`</span>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | TCP/443                              | Android OS connectivity checks for Wi-Fi/Mobile network connections       |
    | <span style={{ display: 'block', marginBottom: '3px' }}>`mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`mtalk4.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt1-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt2-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt3-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt4-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt5-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt6-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt7-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`alt8-mtalk.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`android.apis.google.com`</span><span style={{ display: 'block', marginBottom: '3px' }}>`device-provisioning.googleapis.com`</span> | TCP/443, 5228-5230                   | FCM connectivity for devices behind organizational firewalls              |
    | `time.google.com`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | UDP/123                              | NTP server access required during device provisioning                     |
  </Tab>
</Tabs>

## TLS Versions and Cipher Suites

Per Apple's Platform Security guide, built-in apps and services on macOS, iOS, tvOS, and iPadOS devices will automatically prefer cipher suites with perfect forward secrecy. This is also true in the case where a developer uses a high-level networking API such as CFNetwork. The Iru Agent leverages these high-level networking APIs.

We encourage you to read Apple's Platform Security Guide to better understand these features, especially the TLS network security section, which can be found [here](https://support.apple.com/guide/security/tls-network-security-sec7b0a3b0b/web).

The domains used for MDM and Iru Agent communication are unique to your tenant. See [Determine Your Unique Device Domains](#determine-your-unique-device-domains) for how to find yours. You can inspect your tenant's domains using a tool such as [Qualys SSL Server Test](https://www.ssllabs.com/ssltest/) to understand which ciphers are currently supported by Iru.

### Supported TLS Protocols

Iru supports the following TLS protocol versions:

| <Icon icon="shield" size={14} /> Protocol | <Icon icon="circle-check" size={14} /> Supported                                                                       | <Icon icon="circle-info" size={14} /> Notes |
| ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ------------------------------------------- |
| TLS 1.2                                   | <Icon icon="circle-check" size={14} color="#16a34a" style={{ display: 'inline-flex', verticalAlign: 'middle' }} /> Yes | Server negotiated using No-SNI              |
| TLS 1.1                                   | <Icon icon="circle-check" size={14} color="#16a34a" style={{ display: 'inline-flex', verticalAlign: 'middle' }} /> Yes |                                             |
| TLS 1.0                                   | <Icon icon="circle-check" size={14} color="#16a34a" style={{ display: 'inline-flex', verticalAlign: 'middle' }} /> Yes | Server negotiated using No-SNI              |
| TLS 1.3                                   | <Icon icon="circle-xmark" size={14} color="#dc2626" style={{ display: 'inline-flex', verticalAlign: 'middle' }} /> No  |                                             |
| SSL 3                                     | <Icon icon="circle-xmark" size={14} color="#dc2626" style={{ display: 'inline-flex', verticalAlign: 'middle' }} /> No  |                                             |
| SSL 2                                     | <Icon icon="circle-xmark" size={14} color="#dc2626" style={{ display: 'inline-flex', verticalAlign: 'middle' }} /> No  |                                             |

### Cipher Suites

<AccordionGroup>
  <Accordion title="TLS 1.2 in server preferred order">
    * `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256`
    * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256`
    * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA`
    * `TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384`
    * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384`
    * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA`
    * `TLS_RSA_WITH_AES_128_GCM_SHA256`
    * `TLS_RSA_WITH_AES_128_CBC_SHA256`
    * `TLS_RSA_WITH_AES_128_CBC_SHA`
    * `TLS_RSA_WITH_AES_256_GCM_SHA384`
    * `TLS_RSA_WITH_AES_256_CBC_SHA256`
    * `TLS_RSA_WITH_AES_256_CBC_SHA`
  </Accordion>

  <Accordion title="TLS 1.1 in server preferred order">
    * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA`
    * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA`
    * `TLS_RSA_WITH_AES_128_CBC_SHA`
    * `TLS_RSA_WITH_AES_256_CBC_SHA`
  </Accordion>

  <Accordion title="TLS 1.0 in server preferred order">
    * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA`
    * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA`
    * `TLS_RSA_WITH_AES_128_CBC_SHA`
    * `TLS_RSA_WITH_AES_256_CBC_SHA`
  </Accordion>
</AccordionGroup>
