IP Scan Between Microsoft Clients on Port :7680 ?

TL;DR: If you experience poor network performance on your wireless notebook, Microsoft may be using your device as a download server without your consent.

Problem: I noticed a high number of requests between Windows clients in different network zones on a customer’s firewall. It appeared that allmost every client was attempting to connect to allmest all other clients on TCP port :7680. The network consists of approximately 300 clients, and I observed around 45 connection requests per second.

Discussion: These clients are separated for security reasons and do not use the same domain controller but are part of the same Microsoft enterprise account. The cause of this behavior is a Microsoft feature called Delivery Optimization, which is used for downloading apps and updates.
(See: Microsoft Docs)

It seems that Microsoft has enabled a download server on every client without explicit consent. With default settings, this “feature” ignores network boundaries. I observed connection attempts between clients in different network zones, including VPN-connected devices and remote/home office users. WLAN clients are also affected, meaning Microsoft is consuming Wi-Fi bandwidth on client notebooks for its download distribution.

Solution: Avoid using Microsoft products, or disable this “feature” on all Microsoft clients that you do not want to act as download servers. You can find instructions here: How to Disable Delivery Optimization