*.microsoft.com may be allowed through on Microsoft EdgeMicrosoft Edge uses its own internal DNS which may use IP addresses that are not known to NSX / other DNS.
Disable the Microsoft Edge internal DNS on all VMs or prohibit the use of Edge to ensure this feature works correctly.