cancel
Showing results for 
Search instead for 
Did you mean: 
vvadim
Level 9
Report Inappropriate Content
Message 1 of 4

Configuring MWG for MS Azure AD Hybrid Join

Jump to solution

Hello All,

In our infrastructure we have:
1) Proxy Server- McAfee Web Gateway (7.7.2.14.0)
2) On-premise Active Directory, DC based  on Win Server 2016 1607 Datacenter
3) End user OS Windows 10 with different build versions (1607, 1703,1709, 1803)

What we are going to achieve
We are going to implement Microsoft Azure AD Hybrid Join, and one of the Microsoft prerequisite of deployment is this technology
1)  proxy server should be capable to authenticate a Windows 10 computers, because a
device registration (registration in Azure AD) using a machine context
https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan

 

2) “For Windows 10 devices on version 1703 or earlier, if you organization requires access to the Internet via an outbound proxy, you must implement Web Proxy Auto-Dicovery to
enable Windows 10 computers to register Azure AD”, - https:/docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-manual
Now we are assign proxy settings via GPO for IE browser not for machine.

Could you please clarify the points above and do we able to configure our proxy server based on mentioned statements?

Thank you!

1 Solution

Accepted Solutions
vvadim
Level 9
Report Inappropriate Content
Message 4 of 4

Re: Configuring MWG for MS Azure AD Hybrid Join

Jump to solution

Looks like solution is add the McAfee maintained list Related to Microsoft Azure ip ranges to Office 365  bypass ruleset with the same actions and params

3 Replies
McAfee Employee aloksard
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Configuring MWG for MS Azure AD Hybrid Join

Jump to solution

Hi,

Hope you are doing well.

Yes proxy server is  capable to authenticate a Windows 10 computers and also WPAD config can be done.

 

Please refer below links for some information on this:-

https://community.mcafee.com/t5/Documents/Web-Gateway-Hosting-the-proxy-pac-wpad-dat/ta-p/554253

 

https://kc.mcafee.com/corporate/index?page=content&id=KB67177

 

 

Regards

Alok Sarda

Highlighted
vvadim
Level 9
Report Inappropriate Content
Message 3 of 4

Re: Configuring MWG for MS Azure AD Hybrid Join

Jump to solution

Hi, thanks for reply.

We're using WPAD-file and Bypassing for Office 365 and other Microsoft services ruleset was implemented as it describes here: https://docs.mcafee.com/bundle/web-gateway-7.7.1-product-guide-unmanaged/page/GUID-C226486F-B963-42A... and here: https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/27000/PD27503/en_US/...


But we have problem with devises without autentification.
I has modify rule with bypass adding section for unauthorized, but I can't attach here any screen or file to show you.

vvadim
Level 9
Report Inappropriate Content
Message 4 of 4

Re: Configuring MWG for MS Azure AD Hybrid Join

Jump to solution

Looks like solution is add the McAfee maintained list Related to Microsoft Azure ip ranges to Office 365  bypass ruleset with the same actions and params

McAfee ePO Support Center Plug-in
Check out the new McAfee ePO Support Center. Simply access the ePO Software Manager and follow the instructions in the Product Guide for the most commonly used utilities, top known issues announcements, search the knowledgebase for product documentation, and server status and statistics – all from within ePO.