This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hybrid Azure join behind a Sophos SG UTM

I'm trying to Hybrid Azure join our devices on our corporate network.

We use a UTM for firewall and Web Filtering.  Normally web traffic hits the web filter when using a browser(PAC file). The required URLS for Azure Hybrid join are allowed through this proxy server. The problem is that the process of joining the device(Proxy direct) is not aware of these proxy settings so the traffic is never directed to the web filter. Instead it goes to the firewall. The firewall explicitly blocks this traffic. We need to know the IP address ranges of the URLs required for this operation so we can allow this traffic to pass through the Firewall. Microsoft can only send me to their 365 URLs and IP addresses but it's a very long list and the blocked IP addresses don't seem to be listed.

Has anyone been able to find out the IP address ranges which are required for this operation or has anyone been able to get this working a different way?

We have been able to get this to work by manually setting the proxy server on a client but this then causes issues with Teams and SCCM.

​The URLS  login.microsoftonline.comand device.login.microsoftonline.com
Thanks in advance.


This thread was automatically locked due to age.
  • Have you tried the Azure form at Microsoft?  This problem should plague all firewalls.

    I just Googled site:community.sophos.com Azure join and found some references that might be helpful.

    Let us know the magic!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA