Version 14+ Kiosk Whitelisting Guide

Last updated: August 8, 2026

What are the domains/IP addresses that I need to whitelist for my GRUBBRR device(s) to function?


The table below lists the essential whitelisting options for your GRUBBRR Tizen or Windows device operating on version 14.x of our Kiosk application. 

Note: All whitelisted addresses use TCP protocols unless otherwise noted in the table. 

Kiosk Whitelisting Requirements

URL
IP Address(es)
Port Purpose
console.grubbrr.com
See Note B 443

Allows the kiosk to download data from and upload data to the GRUBBRR Console

prod-grubbrr.identity.us.auth0.com 104.19.167.1/20* 443

GRUBBRR account / identity provider

builds.grubbrr.net 13.107.246.1/28* 443

Allows the kiosk to download updated software versions from application storage servers.

api.nge.grubbrr.com 20.119.0.28 443

Enables real-time, cloud-based communication between the Kiosk and the Console

stgngeprodeastus.blob.core.windows.net
52.239.169.1/23* 443

Microsoft Azure data storage

api.vfipayna.com/ipchapi/rh.aspx
api.vfipayna2.com/ipchapi/rh.aspx
vhq.connect.verifone.com

199.71.106.52

199.71.106.58

443

Allows the Verifone Gateway to process orders

*.sentry.io See Note B 443

Collects Kiosk App Logs and manages general Error Tracking

*.pusher.com
*.pusherapp.com
See Note B 443

Allows the kiosk to receive notifications from the GRUBBRR Portal

ik.imagekit.io See Note B 443

Allows the kiosk to communicate with media storage servers. These host the kiosk screensavers, images, and other UI elements of the kiosk software.

fonts.gstatic.com See Note B 443

Gives the Kiosk access to Google Font Libraries

eastus-8.in.applicationinsights.azure.com See Note B 443

Gives the Kiosk access to Microsoft Azure App Insights telemetry

Remote Management Whitelisting Requirements

URL
IP Address(es)
Port Purpose
*.teamviewer.com See Note B












80, 443

Enables remote control of the Kiosk using TeamViewer

*.manage.microsoft.com 443

The URLs and ports here enable the effective and secure management of remote devices via Microsoft Intune. 

 

If CIDR blocks are needed,
please review Microsoft’s Documentation.


This consolidated list is designed to ensure stable and secure

communication for Windows Remote Management Services, TeamViewer, Windows Update, NTP,
Autopilot, Remote Help, Edge, and the Windows Store.

EnterpriseEnrollment.manage.microsoft.com 443
*.update.microsoft.com 80, 443
*.autodeploy.mp.microsoft.com 443
*.support.services.microsoft.com 443
remoteassistance.support.services.microsoft.com 443
*.attest.azure.net 443
login.microsoftonline.com 443
graph.windows.net 443
*.azureedge.net 443
time.windows.com

UDP

Port 123

*.do.dsp.mp.microsoft.com 443
*.dl.delivery.mp.microsoft.com 443
edge.microsoft.com 443
*.msftconnecttest.com 443
*.msedge.net 443
*.microsoft.com 443
*.wns.windows.com 443
*.azure.com 443
*.login.live.com 443
*.samsungqbe.com
23.62.46.116
23.62.46.119
50.17.7.32
54.162.159.37
54.237.106.192
34.160.215.19
18.140.79.177
18.138.183.195
52.12.66.253
52.12.93.31
3.33.227.249
15.197.205.27
http://grubbrr.samsungcms.com/
remote-device.samsungcms.com 
remote.samsungcms.com
3.168.88.61
44.235.172.254
44.240.15.69
35.167.33.46
44.241.9.194
44.240.15.69
44.235.172.254
18.239.194.3
34.241.91.236
54.154.12.37
20.114.67.142
wp.greenwichmeantime.com
See Note B

80
443
3030
7002
7001
8000
8001
8002

Tizen OS Only

Allows GRUBBRR support to provide remote assistance to the kiosk using MagicInfo, and allows the kiosk to automatically track the correct time. 

Notes

Note A: You can whitelist via entries in the "Address" or "IPs" column; you do not need to do both

Note B: These dynamic IP address ranges are managed by their corresponding cloud service providers and are NOT guaranteed to remain unchanged. It is highly recommended to use Domain Name-based whitelisting on your firewall to resolve these URLs and permit access based on the corresponding dynamic IP addresses.