A member of your organisation is attending an NKD Agility class that uses Minecraft Education. The trainer hosts the game world and participants join it remotely. This page lists what your network and devices must allow. The participant’s own steps are in Minecraft Education setup for participants.

How it works

  • We provide the account and licence. Minecraft Education only lets players in the same Microsoft 365 organisation play together. Each participant signs in with an account in our tenant, with a Minecraft Education licence we assign. They do not use your organisation’s accounts or licences.
  • The game is peer-to-peer. The trainer’s device hosts the world. Players connect through Microsoft’s signalling service and, where needed, Microsoft’s relay. No port forwarding is needed on your network.
  • Everyone must run the same version. If your organisation blocks app updates, the participant’s copy may fall behind and they will not be able to join.

Devices

  • Windows 10 or 11 (64-bit), macOS 14, ChromeOS 114 with Google Play, iPadOS 15, or Android 8.
  • Not supported: Linux, ChromeOS Flex, Windows Server, emulators.
  • Minimum 2 GB memory and 2 GB storage; 8 GB memory recommended.
  • On Windows, the Microsoft Store version and the desktop installer cannot both be installed. Managed devices can deploy it with Intune (Microsoft Store app), WinGet, Group Policy or the desktop installer.
  • The participant needs permission to install the app, or you need to install it for them.

Network

Allow outbound HTTPS (TCP 443) to:

Address Purpose
*.minecrafteduservices.com Sign-in, multiplayer
login.microsoftonline.com, aadcdn.msauth.net Microsoft sign-in
*.minecraft-services.net Multiplayer signalling (WebSocket, wss://signal.franchise.minecraft-services.net)
*.xboxlive.com, *.playfabapi.com, education.minecraft.net Game library content
graph.microsoft.com, *.sharepoint.com Saving worlds
meedownloads.blob.core.windows.net Updates

For multiplayer, also allow:

  • Relay (STUN and TURN): turn.azure.com and world.relay.skype.com, IP range 20.202.0.0/16, on remote TCP 443 and remote UDP 3478–3481.
  • Game traffic: outbound UDP on ephemeral ports. The host’s operating system picks the port and passes it to the joining device through the signalling service.

On Windows, allow the process Minecraft.AdalServer.exe to run during sign-in. On Chromebooks that use SSL decryption, add the certificate-serving addresses to your bypass list.

Things that commonly break it

  • Blocking outbound UDP or the 20.202.0.0/16 range stops multiplayer even when sign-in works.
  • Content filters or antivirus blocking *.minecrafteduservices.com cause “Unable to connect to world” or “Unable to access the service”.
  • Tenant restrictions. If your organisation only allows sign-in to its own Microsoft tenant, the participant cannot sign in to ours. Allow our tenant for this purpose, or let the participant use a personal device on a network outside that policy.
  • VPNs and proxies that send all traffic through TCP-only inspection can block the UDP path. Exclude Minecraft Education traffic from the VPN or proxy, or join from outside it.

Testing

We run a practice join with every participant before the class. If it fails, we will send you the error the participant saw.

The source for these requirements is Microsoft’s Minecraft Education IT admin guide and system requirements. Check them for any changes since this page was written.