<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Excluding MS Teams from GlobalProtect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415539#M1469</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The MS-Teams application resides in the user direcetory, hence whitelisting based on the executable might not work here. Whitelisting the executable would also grant access to your sharepoint if it is called by MS-Teams.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to the URLs (plus "Split DNS"), we have added a few IP ranges which are used by MS-Teams for real-time data (audio/video). On the O365 URLs and IP addresses page (&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide" target="_blank"&gt;https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide&lt;/A&gt;) they are listed with id 11.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Browsing &lt;A href="https://connectivity.office.com/" target="_blank"&gt;https://connectivity.office.com/&lt;/A&gt; tells you if the connection took the path you expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp; Joerg&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 06:39:28 GMT</pubDate>
    <dc:creator>JoergSchuetter</dc:creator>
    <dc:date>2021-06-28T06:39:28Z</dc:date>
    <item>
      <title>Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415488#M1466</link>
      <description>&lt;P&gt;I'm trying to exclude MS Teams traffic from GlobalProtect.&amp;nbsp; We are using the entire O365 platform but I only want to exclude MS Teams.&amp;nbsp; Has anyone been able to successfully get this to work?&amp;nbsp; I found some older community posts but most seemed to have inconsistent results.&amp;nbsp; &amp;nbsp;I'm running PAN OS 9.0.x and GP 5.2.6.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is excluding&amp;nbsp; "%LOCALAPPDATA%\Microsoft\Teams\current\Teams.exe"&amp;nbsp; supported and would that be all that is needed?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried something similar with Zoom but when zoom was installed into&amp;nbsp;&lt;SPAN&gt;%USERPROFILE%\&lt;/SPAN&gt;&lt;EM&gt;AppData&lt;/EM&gt;&lt;SPAN&gt;\Roaming\Zoom, it did not work.&amp;nbsp; I had to install zoom into&amp;nbsp;C:\Program Files (x86)\Zoom to get that to exclude correctly&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 00:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415488#M1466</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2021-06-28T00:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415501#M1468</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have MS teams excluded from the GP using URLs&lt;/P&gt;
&lt;P&gt;There are lot of urls that need to be excluded and it is working fine for us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 03:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415501#M1468</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-06-28T03:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415539#M1469</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The MS-Teams application resides in the user direcetory, hence whitelisting based on the executable might not work here. Whitelisting the executable would also grant access to your sharepoint if it is called by MS-Teams.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to the URLs (plus "Split DNS"), we have added a few IP ranges which are used by MS-Teams for real-time data (audio/video). On the O365 URLs and IP addresses page (&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide" target="_blank"&gt;https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide&lt;/A&gt;) they are listed with id 11.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Browsing &lt;A href="https://connectivity.office.com/" target="_blank"&gt;https://connectivity.office.com/&lt;/A&gt; tells you if the connection took the path you expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp; Joerg&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 06:39:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415539#M1469</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-06-28T06:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415589#M1470</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83320"&gt;@JoergSchuetter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did find this article previously, but seemed like it was too easy to be all that is needed.&amp;nbsp; Are you saying you were able to get it to work by excluding only these IP ranges and ports,&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;13.107.64.0/18, 52.112.0.0/14, 52.120.0.0/14 with ports 3478,3479,3480,3481?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what the other URLS listed under ID 11 but under the same Skype for Business Online and Microsoft Teams section?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;mind sharing your list of URLS that you excluded?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 12:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415589#M1470</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2021-06-28T12:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415823#M1472</link>
      <description>&lt;P&gt;We are using the following IDs concerning URLs: 1,3,8,9,11,12,13,16,17,22,127,154&lt;/P&gt;&lt;P&gt;*.broadcast.skype.com&lt;BR /&gt;*.keydelivery.mediaservices.windows.net&lt;BR /&gt;*.lync.com&lt;BR /&gt;*.msecnd.net&lt;BR /&gt;*.outlook.office.com&lt;BR /&gt;*.protection.outlook.com&lt;BR /&gt;*.skypeforbusiness.com&lt;BR /&gt;*.streaming.mediaservices.windows.net&lt;BR /&gt;*.teams.microsoft.com&lt;BR /&gt;ajax.aspnetcdn.com&lt;BR /&gt;aka.ms&lt;BR /&gt;amp.azure.net&lt;BR /&gt;attachments.office.net&lt;BR /&gt;autodiscover.&amp;lt;your company here&amp;gt;.onmicrosoft.com&lt;BR /&gt;mlccdn.blob.core.windows.net&lt;BR /&gt;outlook.office.com&lt;BR /&gt;outlook.office365.com&lt;BR /&gt;r1.res.office365.com&lt;BR /&gt;r3.res.office365.com&lt;BR /&gt;r4.res.office365.com&lt;BR /&gt;teams.microsoft.com&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 08:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415823#M1472</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-06-29T08:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415955#M1475</link>
      <description>&lt;P&gt;Thanks for the info.&amp;nbsp; Based on some of the URLs you posted, there are exclusions other than MS Teams in there, which I can't have&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far, I have only excluded these optimized ranges 13.107.64.0/18 ,52.112.0.0/14,52.120.0.0/14.&amp;nbsp; &amp;nbsp;Seems to be working okay for the most part, although I still see a little traffic for IPs within these ranges on the firewall&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 15:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/415955#M1475</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2021-06-29T15:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/416016#M1476</link>
      <description>&lt;P&gt;The traffic you are seeing stems from the fact that MS-Teams sends connection probes via all interfaces (GP-Interface and LAN-Interface). It will pick the interface it identifies as "better".&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 17:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/416016#M1476</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-06-29T17:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Excluding MS Teams from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/416025#M1477</link>
      <description>&lt;P&gt;Good point!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 17:34:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/excluding-ms-teams-from-globalprotect/m-p/416025#M1477</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2021-06-29T17:34:47Z</dc:date>
    </item>
  </channel>
</rss>

