Lync (Skype for Business) and Office 365 SSL decrypt

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Lync (Skype for Business) and Office 365 SSL decrypt

L0 Member

We are considering to implement SSL decrypt specifically for Office 365 and Lync (Skype for Business) traffic. What we found is that the you are unable to join non-federated meetings from external vendors that also uses Lync. Obviously we don't allow uncontrolled direct access for our employees, and currently without SSL decrypt we see the initial SYN packet when trying to join a meeting with the vendor as SSL traffic. This defeats the purpose of controlling access. We are of the opinion that by implementing SSL decrypt we will have better control over this traffic provising specifically these ms-lync APP-ID traffic unrestricted to our users.

 

Note* We are not subscribed to an URL database (Brighcloud or PAN-DB) and it seems to go hand in hand enabling SSL decrypt.

 

  • So does anyone have any experience with decrypting Lync traffic / Office 365 and what is your experience so far using it? 
  • Any caveats? 
  • I'm also interested in if anyone is decrypting everything except the industry standard exclusions like Financial and sites that break?
  • If anyone can also share their experience with certificate pinning while using SSL decrypt. Seems to be a manual process where you have to exclude site only after discovering them breaking. Having 10 000 employees and considering the commit times on PANs this may be a daunting task.

 

Appreciate it

Thanks

 

0 REPLIES 0
  • 1817 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!