Skip to main content
jiahoong112
Staff
Staff
February 16, 2026

Technical Tip: FortiSASE bypass for a Microsoft Windows update

  • February 16, 2026
  • 0 replies
  • 414 views
Description This article describes how to configure bypass for Microsoft Update traffic for FortiSASE SIA VPN. This is done in the endpoint profile configuration of FortiSASE.
Scope FortiSASE feature release.
Solution
  1. In the FortiSASE Portal, go to Endpoint Management -> Endpoint Profiles.
  2. Create or select an existing Endpoint Profile of choice. Under the Connection section, scroll down to 'Steering bypass destinations'.
  3. Under the 'Steering bypass destinations', the following Infrastructure and FQDN objects should be added.

 

Infrastructure objects:

  • Add the infrastructure objects: Microsoft-Microsoft.Update and Microsoft-WNS.

 

jiahoong112_0-1770964365485.png

 

FQDN:

  • definitionupdates.microsoft.com
  • prod.do.dsp.mp.microsoft.com
  • dl.delivery.mp.microsoft.com
  • windowsupdate.com
  • delivery.mp.microsoft.com
  • update.microsoft.com
  • windowsupdate.microsoft.com
  • adl.windows.com
  • tsfe.trafficshaping.dsp.mp.microsoft.com
  • api.cdp.microsoft.com

 

Refer to this resource for the comprehensive list of FQDN objects related to the Windows Update: Microsoft Windows Update.

 

Note: Some IPs may belong to other ISDB objects such as 'Akamai-CDN'. When this happens, traffic to those specific destinations may still pass through the VPN tunnel to FortiSASE. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!