Hello All,
In our infrastructure we have:
1) Proxy Server- McAfee Web Gateway (7.7.2.14.0)
2) On-premise Active Directory, DC based on Win Server 2016 1607 Datacenter
3) End user OS Windows 10 with different build versions (1607, 1703,1709, 1803)
What we are going to achieve
We are going to implement Microsoft Azure AD Hybrid Join, and one of the Microsoft prerequisite of deployment is this technology
1) proxy server should be capable to authenticate a Windows 10 computers, because a
device registration (registration in Azure AD) using a machine context
https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan
2) “For Windows 10 devices on version 1703 or earlier, if you organization requires access to the Internet via an outbound proxy, you must implement Web Proxy Auto-Dicovery to
enable Windows 10 computers to register Azure AD”, - https:/docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-manual
Now we are assign proxy settings via GPO for IE browser not for machine.
Could you please clarify the points above and do we able to configure our proxy server based on mentioned statements?
Thank you!
Solved! Go to Solution.
Looks like solution is add the McAfee maintained list Related to Microsoft Azure ip ranges to Office 365 bypass ruleset with the same actions and params
Hi,
Hope you are doing well.
Yes proxy server is capable to authenticate a Windows 10 computers and also WPAD config can be done.
Please refer below links for some information on this:-
https://community.mcafee.com/t5/Documents/Web-Gateway-Hosting-the-proxy-pac-wpad-dat/ta-p/554253
https://kc.mcafee.com/corporate/index?page=content&id=KB67177
Regards
Alok Sarda
Hi, thanks for reply.
We're using WPAD-file and Bypassing for Office 365 and other Microsoft services ruleset was implemented as it describes here: https://docs.mcafee.com/bundle/web-gateway-7.7.1-product-guide-unmanaged/page/GUID-C226486F-B963-42A... and here: https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/27000/PD27503/en_US/...
But we have problem with devises without autentification.
I has modify rule with bypass adding section for unauthorized, but I can't attach here any screen or file to show you.
Looks like solution is add the McAfee maintained list Related to Microsoft Azure ip ranges to Office 365 bypass ruleset with the same actions and params
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA