logo
search
MFA & Verification Issues

How to Configure Firewall Rules for Microsoft Authenticator on iOS and Android

Maira MehtabMaira Mehtab Sep 20, 2026 869 views

Question details

The user needs to configure a captive portal firewall to allow Microsoft Authenticator traffic so that push notifications work correctly across mobile platforms.

Product
Microsoft Authenticator
Device & OS
iOS and Android
Scenario
Using Microsoft Authenticator behind a captive portal firewall for multi-factor authentication.
Observed behavior
Push notifications are failing on Android devices and only working on older iOS versions behind the captive portal firewall.
Before you start

Ensure you have administrative access to your network's captive portal firewall settings and the ability to whitelist specific IP ranges and ports.

Solution 1Recommended

Consult Official Microsoft Authenticator Guidance and Support

Because firewall configurations and mobile OS notification services (APNs for iOS, FCM for Android) vary greatly, reaching out to official support channels is highly recommended.

Network-specific issues involving captive portals often require advanced packet tracing and firewall-specific configuration.

Microsoft provides dedicated forums for enterprise mobility and security where specialists can review your exact firewall model and OS version constraints.

1
Review Official Documentation

Check the official Microsoft endpoint documentation for the specific Azure Active Directory URLs and IP ranges required by Microsoft Authenticator.

2
Visit Microsoft Q&A

Navigate to the Microsoft Q&A forum (learn.microsoft.com/en-us/answers) and search for the 'Microsoft Authenticator' tag.

3
Post Your Specific Issue

Create a new thread detailing your captive portal firewall brand, the specific Android versions failing, and the iOS versions where notifications succeed to get targeted specialist assistance.

Provide Detailed Logs: When posting on Microsoft Q&A, including firewall drop logs and app correlation IDs will help Microsoft engineers diagnose the issue faster.
Free Microsoft Office alternative

Need a Lightweight, Hassle-Free Office Suite? Try WPS Office

If you are dealing with complex Microsoft enterprise setups and authentication hurdles, you might prefer a simpler, lightweight office suite for your personal or team document needs. WPS Office provides excellent compatibility with Microsoft Word, Excel, and PowerPoint files without the heavy enterprise overhead.

  1. 1. Visit the Official Website: Go to wps.com to download the free WPS Office suite for your operating system.
  2. 2. Install the Application: Run the downloaded installer and follow the simple on-screen instructions to set up WPS Office on your device.
  3. 3. Open Microsoft Formats Directly: Double-click any existing .docx, .xlsx, or .pptx file to open and edit it instantly within WPS Office without formatting loss.
Highly compatible with Microsoft Office formats (.docx, .xlsx, .pptx)Lightweight and fast to install on desktop and mobile devicesFree to use with a familiar, user-friendly interfaceSeamless cross-platform support for Windows, Mac, iOS, and Android
QA img-9

Frequently Asked Questions

Why are Microsoft Authenticator push notifications delayed or failing on Android?

Android relies on Firebase Cloud Messaging (FCM). If your captive portal or firewall blocks TCP ports 5228-5230 or restricts background data before the user authenticates to the network, the Authenticator app cannot receive the push notification from Microsoft's servers.

Which ports need to be open for iOS Microsoft Authenticator notifications?

For iOS devices, your network firewall must allow outbound connections to the Apple Push Notification service (APNs) primarily on TCP port 5223, as well as port 443 for fallback communication and port 2197 for provider API traffic.

Can I use Microsoft Authenticator without push notifications?

Yes. If push notifications are currently blocked by a captive portal firewall, you can open the Microsoft Authenticator app manually and use the 6-digit time-based one-time password (TOTP) code generated on the screen to complete your sign-in process.