Version 14+ Kiosk Whitelisting Guide
Last updated: August 8, 2026
What are the domains/IP addresses that I need to whitelist for my GRUBBRR device(s) to function?
The table below lists the essential whitelisting options for your GRUBBRR Tizen or Windows device operating on version 14.x of our Kiosk application.
Note: All whitelisted addresses use TCP protocols unless otherwise noted in the table.
Kiosk Whitelisting Requirements
| URL | IP Address(es) | Port | Purpose |
| console.grubbrr.com | See Note B | 443 |
Allows the kiosk to download data from and upload data to the GRUBBRR Console |
| prod-grubbrr.identity.us.auth0.com | 104.19.167.1/20* | 443 |
GRUBBRR account / identity provider |
| builds.grubbrr.net | 13.107.246.1/28* | 443 |
Allows the kiosk to download updated software versions from application storage servers. |
| api.nge.grubbrr.com | 20.119.0.28 | 443 |
Enables real-time, cloud-based communication between the Kiosk and the Console |
| stgngeprodeastus.blob.core.windows.net | 52.239.169.1/23* | 443 |
Microsoft Azure data storage |
|
api.vfipayna.com/ipchapi/rh.aspx |
199.71.106.52 199.71.106.58 | 443 |
Allows the Verifone Gateway to process orders |
| *.sentry.io | See Note B | 443 |
Collects Kiosk App Logs and manages general Error Tracking |
| *.pusher.com *.pusherapp.com | See Note B | 443 |
Allows the kiosk to receive notifications from the GRUBBRR Portal |
| ik.imagekit.io | See Note B | 443 |
Allows the kiosk to communicate with media storage servers. These host the kiosk screensavers, images, and other UI elements of the kiosk software. |
| fonts.gstatic.com | See Note B | 443 |
Gives the Kiosk access to Google Font Libraries |
| eastus-8.in.applicationinsights.azure.com | See Note B | 443 |
Gives the Kiosk access to Microsoft Azure App Insights telemetry |
Remote Management Whitelisting Requirements
| URL | IP Address(es) | Port | Purpose |
| *.teamviewer.com | See Note B | 80, 443 |
Enables remote control of the Kiosk using TeamViewer |
| *.manage.microsoft.com | 443 |
The URLs and ports here enable the effective and secure management of remote devices via Microsoft Intune.
If CIDR blocks are needed,
| |
| EnterpriseEnrollment.manage.microsoft.com | 443 | ||
| *.update.microsoft.com | 80, 443 | ||
| *.autodeploy.mp.microsoft.com | 443 | ||
| *.support.services.microsoft.com | 443 | ||
| remoteassistance.support.services.microsoft.com | 443 | ||
| *.attest.azure.net | 443 | ||
| login.microsoftonline.com | 443 | ||
| graph.windows.net | 443 | ||
| *.azureedge.net | 443 | ||
| time.windows.com |
UDP Port 123 | ||
| *.do.dsp.mp.microsoft.com | 443 | ||
| *.dl.delivery.mp.microsoft.com | 443 | ||
| edge.microsoft.com | 443 | ||
| *.msftconnecttest.com | 443 | ||
| *.msedge.net | 443 | ||
| *.microsoft.com | 443 | ||
| *.wns.windows.com | 443 | ||
| *.azure.com | 443 | ||
| *.login.live.com | 443 | ||
| *.samsungqbe.com 23.62.46.116 23.62.46.119 50.17.7.32 54.162.159.37 54.237.106.192 34.160.215.19 18.140.79.177 18.138.183.195 52.12.66.253 52.12.93.31 3.33.227.249 15.197.205.27 http://grubbrr.samsungcms.com/ remote-device.samsungcms.com remote.samsungcms.com 3.168.88.61 44.235.172.254 44.240.15.69 35.167.33.46 44.241.9.194 44.240.15.69 44.235.172.254 18.239.194.3 34.241.91.236 54.154.12.37 20.114.67.142 wp.greenwichmeantime.com | See Note B |
80 |
Tizen OS Only Allows GRUBBRR support to provide remote assistance to the kiosk using MagicInfo, and allows the kiosk to automatically track the correct time. |
Notes
Note A: You can whitelist via entries in the "Address" or "IPs" column; you do not need to do both
Note B: These dynamic IP address ranges are managed by their corresponding cloud service providers and are NOT guaranteed to remain unchanged. It is highly recommended to use Domain Name-based whitelisting on your firewall to resolve these URLs and permit access based on the corresponding dynamic IP addresses.