Forum Discussion

Peter Abele's avatar
Peter Abele
Former Employee
Nov 27, 2020

SSL decrypt whitelisting recommended vs supported

Hi Team,

 

I need some clarification regarding supportability of SSL decryption on the proxy against specific O365 endpoints.

I understand that MS recommendation is to whitelist all Optimize and Allow endpoint from SSL Decrypt

But now I'm more interested about in which case is it absolutely required to whitelist from SSL Decrypt?

I know it's a must for EXO Optimize, as Outlook uses certificate pinning, but what about SPO Optimize?

 

Quoting parts of Managing O365 Endpoints article:

"

Optimization methods include:

  • Bypass Optimize endpoints on network devices and services that perform traffic interception, SSL decryption, deep packet inspection, and content filtering.
  • Bypass Allow endpoints on network devices and services that perform traffic interception, SSL decryption, deep packet inspection, and content filtering.

Network optimizations for Allow endpoints can improve the Office 365 user experience, but some customers may choose to scope those optimizations more narrowly to minimize changes to their network."

 

Based on the last sentence I'd assume, that whitelisting Allow endpoints from SSL Decrypt is optional.

As this applies to Allow endpoints only, does it mean that it's a must for Optimize endpoints?

1 Reply

Resources