|
TLS Inspection can often break AutoPilot deployments if not configured correctly, due to: - Autopilot and Intune heavy reliance on certificate pinning.
- Many endpoints use HSTS + HPKP‑like behaviour.
- Some services (notably Azure AD / Entra ID, Windows Update, Intune MDM, Autopilot) will reject re‑signed traffic, even if the proxy is trusted.
These categories should be bypassed from TLS inspection entirely: Microsoft Entra ID (Azure AD) - login.microsoftonline.com
- login.windows.net
- device.login.microsoftonline.com
- enterpriseregistration.windows.net
- device.login.microsoft.com
- aadcdn.msftauth.net
- aadcdn.msauth.net
If these are intercepted, you may experience: - Autopilot white‑screen hang
- "Something went wrong" during OOBE
- MDM enrollment failures
- Conditional Access loops
Windows Autopilot - ztd.dds.microsoft.com
- ztdgph.dds.microsoft.com
- cs.dds.microsoft.com
If these are intercepted, you may experience: - Device never downloads profile
- Stuck at "Just a moment…"
- Autopilot resets fail
Intune MDM + Enrollment - manage.microsoft.com
- dm.microsoft.com
- enterpriseregistration.windows.net
- enrollment.manage.microsoft.com
If these are intercepted, you may experience: - Device enrolls but never syncs
- Apps stuck at "Pending"
- Compliance policies never apply
Windows Update / Store / Content Delivery - *.windowsupdate.com
- *.update.microsoft.com
- *.delivery.mp.microsoft.com
- *.dl.delivery.mp.microsoft.com
- *.storeedgefd.dsx.mp.microsoft.com
If these are intercepted, you may experience: - Autopilot ESP hangs on "Installing apps"
- Win32 apps never download
- Feature updates fail
Microsoft 365 Core Services - *.sharepoint.com
- *.office.com
- *.office365.com
- *.onenote.com
- *.teams.microsoft.com
- *.skype.com
- *.msedge.net
If these are intercepted, you may experience: - Teams sign‑in loops
- OneDrive fails to authenticate
- SharePoint pages fail to load
- Office apps stuck at "Sign in required"
Miscellaneous Scripting Requirements - www.powershellgallery.com
- powershellgallery.com
- psg-prod-eastus.azureedge.net
- onegetcdn.azureedge.net
- go.microsoft.com
- aka.ms
- login.microsoftonline.com
- graph.microsoft.com
Proxy Authentication ConsiderationsAs CC5 and Autopilot enrolment occurs before user signs-ins: - User‑based proxy auth will fail
- Kerberos/NTLM challenges will fail
- Captive portals will break the flow
In order to avoid above: - Device‑based authentication (certificate or IP‑based)
- Transparent proxy mode
- PAC file with direct bypass for Microsoft endpoints
Service Tags (recommended over FQDN/IP allowlists)In order to avoid continuous maintenance: - Microsoft365
- WindowsUpdate
- Intune
- AzureActiveDirectory
- Autopilot
- Office365
- WindowsAutopatch
These are updated automatically by Microsoft and dramatically reduce breakage.
Autopilot ConsiderationsESP (Enrollment Status Page) ESP will hang indefinitely if TLS inspection or filtering blocks: - Win32 app downloads
- Store content
- Windows Update
- Intune MDM sync
In order to address: - Bypass inspection for all Microsoft CDN endpoints
- Ensure *.blob.core.windows.net is allowed
- Ensure *.azureedge.net is allowed
Win32 App Delivery Win32 apps use: - Intune MDM channel
- Azure CDN
- Delivery Optimization
If any of these are blocked, apps never install Delivery Optimization The following Delivery Optimization endpoints must be allowed: - *.do.dsp.mp.microsoft.com
- *.dl.delivery.mp.microsoft.com
Note: Delivery Optimization will also fail under TLS inspection.
Certificate Pinning SummaryThese Microsoft services use certificate pinning and cannot be intercepted:
| Service | TLS Inspection Allowed? | Notes | | Autopilot | No | Fails during OOBE | | Intune MD | No | Fails during enrolment and synchronisation | | Azure AD / Entra ID | No | Token issuance fail | | Windows Updates | No | Updates and ESP fail | | Office 365 | No | Most endpoints will fail | | Teams | No | Media and authorisation will fail | | OneDrive | No | Synchronisation fail | | SharePoint | No | Modern authentication will fail |
|