- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-17-2025 01:02 PM
Hello,
We're adding the Microsoft 365 EDLs from here: EDL Hosting Service. The goal is to allow access to all M365 IPs and URLs outbound.
What's best practice if I have two separate EDLs, one for IPs and one for URLs? I see that IP-based EDLs can be used in the Destination portion of the rule, and URLs appear to be only selectable in the Service/URL Category. Can we combine these onto one rule or would we require multiple?
Any advice would be appreciated.
10-17-2025 03:42 PM
Hi @roryschmitz ,
Great question! Just a heads up, If you were to combine an IP EDL in the destination and a URL EDL in the URL category of a single rule, the traffic would need to match both the destination IP address from the IP EDL *AND* the URL from the URL EDL for that rule to be applied.
In your scenario, the best practice would be to create 2 separate Security Policies that reference the IP EDL and the URL/Domain. EDL.
10-17-2025 03:42 PM
Hi @roryschmitz ,
Great question! Just a heads up, If you were to combine an IP EDL in the destination and a URL EDL in the URL category of a single rule, the traffic would need to match both the destination IP address from the IP EDL *AND* the URL from the URL EDL for that rule to be applied.
In your scenario, the best practice would be to create 2 separate Security Policies that reference the IP EDL and the URL/Domain. EDL.
10-17-2025 05:43 PM
Thanks for that! Is it preferable to also add the respective Palo applications to the rules as well (i.e. OneDrive, Microsoft-base, etc) to restrict it down or keep it more open by leaving it as application-default?
12-04-2025 06:07 AM
Don't use "application-default" in a block rule. In a block rule, if you specify "application-default", then any traffic that is on off-ports will not be blocked. For this reason, the ports in the block rule must be set to "any" if your intent is to block all traffic. "application-default" is really meant for allow rules.
12-08-2025 07:39 AM
Thank you for the clarification on application-defaults and the rule types. Much appreciated.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

