Microsoft Entra Global Secure Access
Fundamentals

Connectors

In brief

The documentation specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151, with new configuration and verification commands. It also adds Windows Server 2016+ prerequisites and clarifies that AutoReuse applies only to TCP.

What Entra admins need to know

Administrators managing high-volume TCP workloads should review available and excluded ports before applying these settings; the ranges must not overlap.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

For guidance on where to install connectors and how to optimize your network, see Optimize traffic flow with Microsoft Entra application proxy.

Expanding ephemeralConfigure dynamic and AutoReuse TCP port rangeranges

Private network connectors initiate outbound TCP and UDP connections to designated destination endpoints. These connections requireconfigured destinations. Each connection requires an available source portsport on the connector host machine. Expanding the ephemeralhost.

For high-volume TCP workloads, configure separate, non-overlapping dynamic and AutoReuse port range can improve the availability of source ports, particularly when you're managing a high volume of concurrent connections.

To view the current dynamic port range on a system, use the following netsh commands:ranges:

  • netsh int ipv4 show dynamicport tcpDynamic TCP range: 49152–65535 (16,384 ports)
  • netsh int ipv4 show dynamicport udp
  • netsh int ipv6 show dynamicport tcp
  • netsh int ipv6 show dynamicport udpAutoReuse TCP range: 10000–49151 (39,152 ports)

Here are sample netsh commandsThe AutoReuse range improves TCP connection scalability by allowing eligible outbound connections to increasereuse a local source port when the ports:complete connection tuple—source IP, source port, destination IP, and destination port—remains unique.

  • netsh int ipv4 set dynamicport tcp start=1025 num=64511
  • netsh int ipv4 set dynamicport udp start=1025 num=64511
  • netsh int ipv6 set dynamicport tcp start=1025 num=64511
  • netsh int ipv6 set dynamicport udp start=1025 num=64511

These commands set the dynamic port range from 1025 to the maximum of 65535. The minimum start port is 1025.

Specifications and sizing requirements

Before you begin:

  • Use Windows Server 2016 or later.
  • Run the commands from an elevated PowerShell session.
  • Confirm that ports 10000–49151 aren't required by applications installed on the connector server.
  • Review the excluded TCP port ranges:
netsh int ipv4 show excludedportrange tcp
netsh int ipv6 show excludedportrange tcp

Configure the port ranges

Configure the dynamic TCP range

netsh int ipv4 set dynamicport tcp start=49152 num=16384
netsh int ipv6 set dynamicport tcp start=49152 num=16384

Configure the AutoReuse TCP range

Set-NetTCPSetting `
  -SettingName Internet,Datacenter,Compat `
  -AutoReusePortRangeStartPort 10000 `
  -AutoReusePortRangeNumberOfPorts 39152

Verify the configuration

netsh int ipv4 show dynamicport tcp
netsh int ipv6 show dynamicport tcp

Get-NetTCPSetting -SettingName Internet,Datacenter,Compat |
  Select-Object SettingName,
    DynamicPortRangeStartPort,
    DynamicPortRangeNumberOfPorts,
    AutoReusePortRangeStartPort,
    AutoReusePortRangeNumberOfPorts

Expected values:

Setting Start port Number of ports End port
Dynamic TCP range 49152 16384 65535
AutoReuse TCP range 10000 39152 49151

Specifications and sizing requirements

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…