Application recognition "ms-teams-audio-video"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Application recognition "ms-teams-audio-video"

L1 Bithead

Hello,

 

I run into behavior that I can't explain.
We make teams available on the virtual desktops (web-based & desktop app)
We only want to block the use of audio and video within the functionality of both teams options.
Users are not allowed to use this (due to performance reasons)

 

In our situation we have configured ssl/tls decryption.
One policy has been defined that blocks the ms-teams-audio-video application.
All other ms-teams* applications are allowed.

However, this ensures that audio and video can be used in both options, the desktop app and web-based.


In the logging I see that the traffic is recognized as ms-teams and I don't see any ms-teams-audio-video.
I expected that as soon as I use audio and video in teams the Palo would recognize this as ms-teams-audio-video

 

Am I misunderstanding things and is this normal behavior? Or does the application recognition not work properly?

 

software-version 10.1.6-h3
apps & threats: 8261-7584

 

With kind regards,
Patrick Pater

3 REPLIES 3

Cyber Elite
Cyber Elite

@PatrickPater,

I can verify that I can replicate this behaviour, but I'm actually wondering if its not related to default decryption exclusions that are in place for several Microsoft domains due to certificate pinning? 

@BPry 
I'm not sure if it's related to certificate pinning. We tested this earlier in May 2022 on a few machines (proof-of-concept) and then the tests were successful.

If it is related to certificate pinning what is the key function of the application ms-teams-audio-video?

L0 Member

tested with ssl decrypt enabled and works great. blocks the call completely but not any of the other features. this will be good for some client terminal servers. now if i could do the same with Zoom and GoTo.

  • 3154 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!