The unexpected SSL interception behavior only occurs with the following condition.
Transparent deployment (Firewall/VPN and WSS Agent)
Trying to connect to Outlook 365
[Note]
Normal HTTPS access, such as https://www.bluecoat.com, is unaffected.
Error message received is:
Security Alert: autodiscover.<companyname>.mail.onmicrosoft.com
This is expected behavior from the Web Security Service.
The client accesses autodiscover.XXXXX.onmicrosoft.com when attempting to connect to Outlook 365.
However, autodiscover.XXXXX.onmicrosoft.com on port 443 does not exist.
The cloud service intercepts this SSL traffic, which causes the error: tcp_error.
Workaround:
Go to Policy ->Threat Protection ->G2 ->Trusted Destinations:
Also, go to Policy ->Content & Malware Analysis ->Scanning Exemptions ->Destinations
Another alternative would be to Disable Auto Discover function from Microsoft site: https://support.microsoft.com/en-us/kb/2212902. Please realize that this is a registry change that would need to be performed on each client machine.