Appendix I: Permitted IP Addresses to access the Check Point Azure Application
When activating protection for Office 365, Email Security installs the Check Point Cloud Security Platform-Emails V2 Azure application in your Microsoft 365 environment.
Check Point uses API calls directed to the Check Point Cloud Security Platform-Emails V2 application to quarantine or restore emails, block users, and perform other actions.
Check Point sends API calls to this application from a specific set of IP networks.
The administrator must treat access attempts from any other IP addresses as unauthorized and potentially originating from threat actors.
Data Regions and Public IP Addresses
-
A limitation in Microsoft prevents the application from restricting access to these IP addresses. Check Point recommends using available tools to monitor and alert users of unauthorized access.
-
Check Point may change the list with sufficient notice provided in advance through the product updates blog.
| Data Region | Public IP address |
|---|---|
| US |
|
| Australia |
|
| Canada |
|
| Europe |
|
| India |
|
| UAE |
|
| UK |
|
Check Point Monitoring Traffic
You may see traffic from the IP address 34.196.171.56 in your logs or access records. The Check Point monitoring infrastructure uses this IP address to perform service health and availability checks. This traffic is expected and can be safely allowed.