According to my application guy, this is true of the Microsoft O365 hybrid solution. It requires direct inbound connections on various ports from largely undefined IP space. I imagine the private VPN limitation (i.e., not having a VPN) is on our side and MS provides something like this...
>Better, find a cloud that doesn't do that shit with changing endpoints and >gives you real VPNs. What sort of >cloud doesn't these days?...?...

