# IP Intelligence Briefing: 20.104.98.143
Classification: Cloud Infrastructure (Microsoft Azure)
Risk Level: LOW (Score: 25/100)
Report Date: 2026-06-21
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP address 20.104.98.143 is a Microsoft Azure cloud compute infrastructure endpoint located in Toronto, Ontario, Canada. The IP presents a low-risk profile with no malicious indicators, no blacklist associations, and consistent cloud infrastructure classification. No immediate blocking or mitigation actions are recommended.
---
## Ownership and Geolocation
| Attribute | Value |
|---|---|
| **Organization** | Microsoft Corporation (MSFT) |
| **ASN** | AS8075 |
| **CIDR Block** | 20.33.0.0/16 |
| **Country** | Canada (CA) |
| **City/Region** | Toronto, ON |
| **Infrastructure Type** | CloudCompute |
| **Provider** | Microsoft Azure |
---
## Threat Assessment
Risk Indicators:
- Risk Score: 25 (Low Risk)
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Threat Feeds: No active threat indicators detected across all monitored sources.
---
## Network Classification
- Cloud Provider: Microsoft Azure
- Hosting Infrastructure: Yes
- CDN: No
- VPN/Proxy: No
- Residential: No
- Mobile Carrier: No
- Anycast: No
- Bogon: No
---
## Neighborhood Analysis (20.104.98.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: 0 (Minimal)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 2
- Neighboring IP: 20.104.98.52 (Risk Score: 25, Authority Score: 50)
The /24 subnet demonstrates low abuse density with Microsoft Azure infrastructure classification.
---
## Relationship Graph
The IP maintains 15 network-level relationships, all associated with Microsoft's MSFT network infrastructure. This indicates the IP is a standard part of Microsoft's distributed cloud infrastructure network.
---
## Observation History
Total Observations: 18 signals
Recent Classification: Minimal Risk (Score: 0.15)
Threat Persistence Days: 0
Is Persistently Malicious: No
Recent Signal Types:
- Network classification (CloudCompute, Microsoft Azure)
- Geolocation inference (Toronto, ON, Canada)
- Routing and control plane indicators
The IP has demonstrated consistent cloud infrastructure classification with no escalation in risk posture over the observation period.
---
## Recommended Actions
Action Level: MONITOR ONLY
- No firewall rules or blocking actions recommended
- Risk score below operational threshold for intervention
- Standard cloud infrastructure traffic pattern observed
Note: If this IP appears in connection logs, it should be permitted. No mitigation actions are warranted based on current intelligence.
---
## Technical Details
- DNS Resolution: No reverse DNS records
- Open Ports: None detected
- TLS Certificates: None detected
- HTTP Services: None detected
- Control Plane: BGP prefix 20.64.0.0/10, stable routing
- DNSSEC: Valid
---
## Conclusion
20.104.98.143 is a legitimate Microsoft Azure cloud infrastructure endpoint with no malicious activity observed. The IP presents standard cloud traffic patterns consistent with enterprise cloud service usage. SOC teams should classify this as trusted infrastructure and permit associated traffic without additional scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Microsoft Corporation |
| ASN | AS8075 |
| Network Name | MSFT |
| CIDR Block | 20.33.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 21% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-29 12:04:52 UTC |
| Last Seen | 2026-06-29 06:24:49 UTC |
| Profile Built | 2026-06-29 06:28:32 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.