URL Whitelist Requirements
URL Whitelist Requirements
Required URLs for DuoKey DKE in hardened environments
Overview
In hardened environments, strict firewall policies are used to block all external traffic by default. The following URLs must be explicitly allowed for DuoKey services to function properly.
DuoKey Cockpit URLs
To use DuoKey Cockpit (Administrator Portal), the following URLs must be explicitly allowed:
| Description | URL |
|---|---|
| DuoKey - Cockpit (Frontend) | https://cockpit.duokey.cloud |
| DuoKey - Cockpit (Backend) | https://cockpit-api.duokey.cloud/ |
| reCAPTCHA | https://www.google.com/recaptcha/*, https://www.gstatic.com/recaptcha/* |
| Fonts | https://fonts.googleapis.com, https://fonts.gstatic.com |
| Dashboard Map | https://*.openstreetmap.org |
| MFA with Google Authenticator | https://chart.googleapis.com |
DKE Web Service URLs
To use the DuoKey DKE Web Service, the following URLs must be explicitly allowed:
| Description | URL |
|---|---|
| DuoKey - Cockpit (Backend) | https://cockpit-api.duokey.cloud/ |
| DuoKey - DKE Web Service | https://<your-uuid>.duokey.cloud |
Replace <your-uuid> with your specific DKE Web Service UUID that you received during setup.
Microsoft endpoints (client outbound)
For DKE to work, Office clients must reach both your DuoKey DKE key service and the Microsoft cloud endpoints below. The flow: the client signs in to Microsoft Entra ID, obtains a token whose audience is your DKE service, then calls your DKE endpoint to wrap/unwrap the second key.
| Purpose | URL / pattern | Port |
|---|---|---|
| Your DuoKey DKE key service | https://<your-uuid>.duokey.cloud/<KeyName> | 443 |
| Microsoft Entra ID sign-in | https://login.microsoftonline.com, https://login.windows.net, https://login.microsoft.com | 443 |
| Azure Rights Management / Purview Information Protection | https://*.aadrm.com, https://*.protection.outlook.com, https://*.informationprotection.azure.com | 443 |
The token issued for DKE carries the issuer https://sts.windows.net/<tenant-id>/
and an audience equal to your DKE service host. Both must match the DKE service
configuration (ValidIssuers, JwtAudience) — a mismatch causes authentication
failures even when the network path is open.
Proxy configuration
Office desktop apps reach the DKE and Rights-Management endpoints over WinHTTP (the system HTTP stack) — not the browser's WinINET proxy. A browser being able to open the DKE key URL is not proof that Office can: the endpoints must be reachable through the WinHTTP proxy.
| Item | Requirement |
|---|---|
| Proxy types | Transparent connectivity and forward proxies — with or without authentication — are supported. |
| WinHTTP proxy | Configure the system proxy so DKE/RMS calls succeed: netsh winhttp show proxy / netsh winhttp set proxy (or netsh winhttp import proxy source=ie). |
| TLS | TLS 1.2 or 1.3 only. The DKE endpoint must present a certificate trusted by the client whose SAN matches the DKE URL configured on the sensitivity label. |
| No SSL inspection | Do not TLS-intercept / re-sign the DKE, Entra and RMS endpoints — inspection breaks the handshake and certificate validation. Add them to the SSL-inspection bypass list. |
The DKE TLS handshake may include an optional client-certificate request, and how Office reacts depends on the build:
- Office builds using the MIP SDK handle the optional request and work with DKE.
- Older builds using MSIPC cannot handle the optional client-certificate request and fail. For those, place a proxy or load balancer in front of the DKE service to intercept and terminate the TLS, so the client never sees the optional certificate request.
- From Office build 2402, desktop apps send
WINHTTP_NO_CLIENT_CERT_CONTEXT(no client certificate). Never require a mandatory client certificate on the DKE endpoint.
A proxy/TLS problem usually shows up as "Word cannot save or create this file" or a hang at "Configuring Information Rights Management" when applying a DKE label — while a browser can still reach the DKE key URL. See Troubleshooting → Network proxy and outbound connectivity.