Configure Office Online Server Access from External Networks
Question details
External users are unable to view documents via Office Online Server when SharePoint Server 2019 is hosted in a DMZ.

- Product
- Office Online Server, SharePoint Server 2019
- Device & OS
- not provided
- Scenario
- Configuring network and firewall settings to allow external document viewing across a DMZ and internal network.
- Observed behavior
- External users cannot access or view documents due to missing or unclear port configurations and HTTPS requirements between the DMZ and internal network.
Before modifying network topologies, ensure you have administrative access to both the SharePoint Server and Office Online Server, as well as the necessary permissions to view and edit your firewall's port rules.
Consult Microsoft Q&A for Specialized DMZ Architectures
Because configuring SharePoint Server 2019 in a DMZ with an internal Office Online Server involves complex enterprise firewall and reverse proxy rules, seeking specialized guidance from Microsoft network experts is recommended.
Placing SharePoint in a DMZ while keeping Office Online Server (OOS) on the internal network requires precise firewall configurations. Incorrectly exposing ports can lead to security vulnerabilities, while overly strict rules will break document rendering.
Gather your current firewall rules, the IP address ranges of your SharePoint DMZ, and the internal IP configurations for your Office Online Server farm.
Open your web browser and visit the official Microsoft Q&A platform at https://learn.microsoft.com/en-us/answers/.
Submit a detailed question describing your SharePoint 2019 DMZ setup, the internal OOS location, and ask for precise guidance on required HTTP/HTTPS port openings and reverse proxy configurations.

Verify Standard Office Online Server Network Requirements
Review the fundamental port and WOPI zone configurations required for Office Online Server to communicate with external users and internal SharePoint servers.
Looking for a simpler way to collaborate on documents? Try WPS Office
If managing complex SharePoint and Office Online Server deployments is too heavy for your current team needs, consider WPS Office. It provides a lightweight, highly compatible alternative for document creation, editing, and sharing without the massive server infrastructure overhead.
- 1. Visit the WPS website: Go to the official WPS Office website to find the appropriate download for your operating system.
- 2. Download and install: Run the lightweight installer and follow the on-screen instructions to set up the software.
- 3. Start collaborating: Open your documents and easily share them with external users using built-in cloud sharing features.

Frequently Asked Questions
What is the correct WOPI zone for external Office Online Server access?
For external access scenarios, the WOPI zone must typically be set to 'external-https'. You can configure this in the SharePoint Management Shell using the command: Set-SPWOPIZone -zone 'external-https'.
Can I place Office Online Server in the DMZ alongside SharePoint?
Microsoft generally recommends placing the Office Online Server farm in the internal network rather than the DMZ to better protect the servers. A reverse proxy should be used in the DMZ to route external HTTPS traffic to the internal OOS farm.
Does Office Online Server require port 80 if we only use HTTPS?
Even if you enforce HTTPS for user connections, internal server-to-server communication or specific hardware load balancer topologies might still require port 80 to be open between the SharePoint servers and the OOS farm.




