Sign up for Office 365
Learn more about Office 365
443
STUN/TCP
Outbound
Audio, video, and application sharing sessions
PSOM/TLS
Data sharing sessions
3478
STUN/UDP
Audio and video sessions
5223
UDP
Ourbound
Lync mobile push notifications
50000-59999
RTP/UDP
Additionally, you should make sure the firewall allows Microsoft Online Services Sign-In Assistant traffic. To do this, take the following steps if you are using Microsoft Forefront Threat Manager Gateway. Similar steps can be taken for other gateways.
Application
Key
Value
msoidsvc
Disable
0
DisableEx
If you are using your own domain name with Office 365, contact your domain name registrar for details about how to make the following changes to your DNS records.
Type
Host name
Destination
TTL
CNAME
sip.yourDomainName.com
sipdir.online.lync.com
1 hour
lyncdiscover.yourDomainName.com
webdir.online.lync.com
Service
Protocol
Port
Weight
Priority
Name
Target
SRV
_sip
_tls
1
100
yourDomainName.com
If your organization supports external communication (that is, connections with other organizations that have external communication enabled), add the following DNS Service (SRV) record as well:
_sipfederationtls
_tcp
5061
sipfed.online.lync.com
If your organization’s Internet proxies or firewalls are configured to block external SRV queries, add the following CNAME entries to your internal DNS server:
lyncdiscoverinternal.yourDomainName.com