Azure AD tenant restrictions

Has anyone had any luck configuring this, I believe I've set it up correctly and ensured proxy is enabled instead of DPI but can still access any tenant?

  • Got to the bottom of this issue, pretty obvious in hindsight but 'wood for the trees etc.' The issue is that having added the Sophos recommended Office 365 exceptions the traffic sent to the login pages is no longer decrypted and therefore doesn't pass through the proxy to receive the additional header.

    Is there a Sophos recommended procedure to work around this?