A custom URL category added to a URL filtering profile on the rule with the required office 365 app-ids may work but it may also be a bit hit and miss.
URL categories are very handy when you want to more accurately match traffic against a specific rule. The good thing about URL categories is these are used as an additional match criteria for the rule. For example if you want to all allow traffic on an office 365 with an SSL and web-browsing dependancy app-ids coming from a trusted zone going to the untrusted zone and a URL category is applied with the appropriate URL matches, all three components will need to match before the traffic will be allowed by this rule.
In my experience they have proven more reliable way of ensuring the right traffic hits the right rule.
@Brandon_Wertz: We added those previously and nothing - traffic was still blocked for some or other reason
In the end we resolved this by adding every IPv4 address MS has listed to Addresses with an appropriate Tag.
In Address Groups we created a Dynamic Group based on the aforementioned Tag.
In Policies we allowed for the Address Group. And now our clients are able to authenticate the Office 365 license. The authentication process is ridiculousloy slow though. With all traffic enabled, license authentication takes a second or two. With the internet restricted and this rule in place...it takes 2 - 3 minutes to authenticate. Very strange this, not to sure where the optimisation must be done.
As we only need to get a license, we only added all IPs relating to Portal and ID.
(Ps: But...to cover our bases - I have also added the IPv6 to Addresses, URLs to URL Category and created an Application Group based on the needed O365 applications in the PAN-2020. Nothing wrong with a little overkill ;-)
Cheers and thanks for the help
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!