Summary
Table of Contents
- Microsoft is changing Dataverse ingress IPs which will consolidate and narrow the service tag IP ranges used by Dataverse infrastructure.
- This impacts outbound connections to Dataverse (including Dataverse TDS) if your network/firewall or web proxy allow-lists specific IP addresses instead of the PowerPlatformInfra regional service tags.
- Admins must review Power Platform URLs and IP ranges and add the appropriate PowerPlatformInfra.<region> service tag(s) to outbound allow-lists; for TDS, ensure port-redirect from non-SSL to SSL is allowed and TDS traffic is permitted by proxy/firewall using IP ranges.
- If you follow Dataverse best practices and allow-list service tags, no action is required; inbound Dataverse traffic is not affected.
Primary Service: Dataverse
Admin Impact: High
User Impact: Low
Release Start: 19 Jun 2026
Release End: 19 Jun 2026
Services: D365 Apps, Dataverse, Dynamics, Power Platform
Category: Stay informed
Tags: History
History
5/23/2026 Item Added to Message Center
Microsoft Message
On June 19, 2026, we will begin updating our Dynamics 365 apps infrastructure in your region which will change the ingress IPs for Dataverse Environments. This update will impact outbound traffic to Dataverse for environments that do not follow best practices for Dataverse configuration.
What action do I need to take?
Please review the Power Platform URLs and IP address ranges and ensure your environment has the service tag IP ranges added to the allowed list. For Dataverse Tabular Data Stream (TDS) connections, please review port redirect from non-SSL to SSL and ensure your connections do not fail due to port redirection by adding Dataverse TDS communication on web proxies using IP ranges to the allowed list.
When configuring outbound firewall rules, allow list the necessary PowerPlatformInfra regional service tag(s) from the following list:
| CRM Domain | Service Tags |
|---|---|
| crm.dynamics.com | PowerPlatformInfra.EastUS, .EastUS2, .WestUS, .CentralUS |
| crm2.dynamics.com | PowerPlatformInfra.BrazilSouth |
| crm3.dynamics.com | PowerPlatformInfra.CanadaCentral, .CanadaEast |
| crm4.dynamics.com | PowerPlatformInfra.WestEurope, .NorthEurope |
| crm5.dynamics.com | PowerPlatformInfra.EastAsia, .SoutheastAsia |
| crm6.dynamics.com | PowerPlatformInfra.AustraliaEast, .AustraliaSoutheast |
| crm7.dynamics.com | PowerPlatformInfra.JapanEast, .JapanWest |
| crm8.dynamics.com | PowerPlatformInfra.CentralIndia, .SouthIndia |
| crm11.dynamics.com | PowerPlatformInfra.UKSouth, .UKWest |
| crm12.dynamics.com | PowerPlatformInfra.FranceCentral, .FranceSouth |
| crm14.dynamics.com | PowerPlatformInfra.SouthAfricaNorth, .SouthAfricaWest |
| crm15.dynamics.com | PowerPlatformInfra.UAENorth, .UAECentral |
| crm16.dynamics.com | PowerPlatformInfra.GermanyWestCentral, .GermanyNorth |
| crm17.dynamics.com | PowerPlatformInfra.SwitzerlandNorth, .SwitzerlandWest |
| crm19.dynamics.com | PowerPlatformInfra.NorwayEast, .NorwayWest |
| crm20.dynamics.com | PowerPlatformInfra.SoutheastAsia |
| crm21.dynamics.com | PowerPlatformInfra.KoreaCentral, .KoreaSouth |
| crm22.dynamics.com | PowerPlatformInfra.SwedenCentral |
| crm23.dynamics.com | PowerPlatformInfra.PolandCentral |
| crm24.dynamics.com | PowerPlatformInfra.ItalyNorth |
Be aware that these IP ranges are subject to change in the future, so please monitor the service tags located here for any updates: Azure service tags overview.
Why is this action needed?
This upcoming change is intended to support better network isolation by consolidating IP ranges into more narrowly scoped ranges, increasing resiliency. If no action is taken, and you allow list specific IP addresses for Microsoft Dataverse instead of service tag IP ranges as recommended, you may be unable to access your Dataverse TDS endpoints and may potentially be unable to access your environment after June 19, 2026. Inbound traffic from Dataverse will not be affected by this update.
If you have already reviewed the above recommendations and confirmed you are following best practices for Dataverse configuration, then no further action is required.