Skip to main content

URL Whitelist Requirements

Applies to:
Firewall ConfigurationProxy SettingsNetwork Security

Overview​

In hardened environments, strict firewall policies are used to block all external traffic by default. The following URLs must be explicitly allowed for DuoKey services to function properly.

DuoKey Cockpit URLs​

To use DuoKey Cockpit (Administrator Portal), the following URLs must be explicitly allowed:

DescriptionURL
DuoKey - Cockpit (Frontend)https://cockpit.duokey.cloud
DuoKey - Cockpit (Backend)https://cockpit-api.duokey.cloud/
reCAPTCHAhttps://www.google.com/recaptcha/*, https://www.gstatic.com/recaptcha/*
Fontshttps://fonts.googleapis.com, https://fonts.gstatic.com
Dashboard Maphttps://*.openstreetmap.org
MFA with Google Authenticatorhttps://chart.googleapis.com

DKE Web Service URLs​

To use the DuoKey DKE Web Service, the following URLs must be explicitly allowed:

DescriptionURL
DuoKey - Cockpit (Backend)https://cockpit-api.duokey.cloud/
DuoKey - DKE Web Servicehttps://<your-uuid>.duokey.cloud
Note

Replace <your-uuid> with your specific DKE Web Service UUID that you received during setup.

Microsoft endpoints (client outbound)​

For DKE to work, Office clients must reach both your DuoKey DKE key service and the Microsoft cloud endpoints below. The flow: the client signs in to Microsoft Entra ID, obtains a token whose audience is your DKE service, then calls your DKE endpoint to wrap/unwrap the second key.

PurposeURL / patternPort
Your DuoKey DKE key servicehttps://<your-uuid>.duokey.cloud/<KeyName>443
Microsoft Entra ID sign-inhttps://login.microsoftonline.com, https://login.windows.net, https://login.microsoft.com443
Azure Rights Management / Purview Information Protectionhttps://*.aadrm.com, https://*.protection.outlook.com, https://*.informationprotection.azure.com443
Note

The token issued for DKE carries the issuer https://sts.windows.net/<tenant-id>/ and an audience equal to your DKE service host. Both must match the DKE service configuration (ValidIssuers, JwtAudience) — a mismatch causes authentication failures even when the network path is open.

Proxy configuration​

Office desktop apps reach the DKE and Rights-Management endpoints over WinHTTP (the system HTTP stack) — not the browser's WinINET proxy. A browser being able to open the DKE key URL is not proof that Office can: the endpoints must be reachable through the WinHTTP proxy.

ItemRequirement
Proxy typesTransparent connectivity and forward proxies — with or without authentication — are supported.
WinHTTP proxyConfigure the system proxy so DKE/RMS calls succeed: netsh winhttp show proxy / netsh winhttp set proxy (or netsh winhttp import proxy source=ie).
TLSTLS 1.2 or 1.3 only. The DKE endpoint must present a certificate trusted by the client whose SAN matches the DKE URL configured on the sensitivity label.
No SSL inspectionDo not TLS-intercept / re-sign the DKE, Entra and RMS endpoints — inspection breaks the handshake and certificate validation. Add them to the SSL-inspection bypass list.
Optional client certificate (mTLS) — mind your Office build

The DKE TLS handshake may include an optional client-certificate request, and how Office reacts depends on the build:

  • Office builds using the MIP SDK handle the optional request and work with DKE.
  • Older builds using MSIPC cannot handle the optional client-certificate request and fail. For those, place a proxy or load balancer in front of the DKE service to intercept and terminate the TLS, so the client never sees the optional certificate request.
  • From Office build 2402, desktop apps send WINHTTP_NO_CLIENT_CERT_CONTEXT (no client certificate). Never require a mandatory client certificate on the DKE endpoint.
Tip

A proxy/TLS problem usually shows up as "Word cannot save or create this file" or a hang at "Configuring Information Rights Management" when applying a DKE label — while a browser can still reach the DKE key URL. See Troubleshooting → Network proxy and outbound connectivity.

Summary​

Required Whitelisted Domains

*.duokey.cloudDuoKey services and DKE endpoints
*.googleapis.comFonts and MFA charts
*.gstatic.comGoogle static resources
*.google.comreCAPTCHA verification