
The way I am applying these rules is that I am allowing all communication to the IP's that I grabbed from the above mentioned URLs, and allowed all communication to go through those IPs with no app-id or security profile restriction. I have also whitelisted all IPs and FQDNs from Office 365: To get passed this, I have followed the guidance from Microsoft on whitelisting IPs and FQDNs that are used by the Intune process. It gets stuck at installing 1 of 20 or 2 of 20 and after a while it eventually times out. The problem we're seeing is that every time we run this process behind a palo alto firewall the downloading of the programs hangs. Once all of these programs are installed the Intune process is completed successfully. Essentially this is an autopilot program that after the client is wiped, it starts downloading programs that are pre defined in our Intune configuration package. We have this Intune process that our team goes through every time a new PC is issued to the user.
