Web Security Service intercepts Office 365 e-mail traffic on port 443 even with SSL disabled
Last Updated April 06, 2018
The unexpected SSL interception behavior only occurs with the following condition.
Transparent deployment (Firewall/VPN and Unified agent)
Trying to connect to Outlook 365
[Note] Normal HTTPS access, such as https://www.bluecoat.com, is unaffected.
This is expected behavior from the Web Security Service.
The client accesses autodiscover.XXXXX.onmicrosoft.com when attempting to connect to Outlook 365. However, autodiscover.XXXXX.onmicrosoft.com on port 443 does not exist. The WSS intercepts this SSL traffic, which causes the error: tcp_error (I couldn’t reach autodiscover.XXXXX.onmicrosoft.com:443).
Add autodiscover.XXXXX.onmicrosoft.com to the Threat Protection bypass list.