In general, your devices and apps will connect to the system so you don't need to open any incoming ports.
However, if you block outgoing access by default within your organisation you will need to allow outbound traffic on the following ports:
Device outbound ports
9300-9319 UDP
Apps outbound ports
9300-9319 TCP and UDP
443 TCP (SSL HTTPS)
User portal outbound ports
443 TCP (SSL HTTPS)