Skip to main content
AmmaIsha
Staff
Staff
April 1, 2026

Technical Tip: Exclude Microsoft Teams traffic from SSL VPN using domain-based split-tunneling

  • April 1, 2026
  • 0 replies
  • 552 views
Description This article provides configuration on FortiClient EMS to exclude MS Teams traffic from SSL VPN using domain based split-tunnel.
Scope FortiClient EMS.
Solution

The Windows version of FortiClient supports source application–based split tunneling, which allows the administrator to define which application traffic bypasses the VPN. Traffic for specific domains can be excluded. Once a domain is excluded, related traffic will not pass through the VPN tunnel. The steps provided assume that a remote SSL VPN profile has already been configured in FortiClient EMS under Endpoint Profiles -> Remote Access.

 

To configure application-based split tunnel, follow these steps:

  1. Navigate to Endpoint Profiles -> Remote Access and edit the desired profile.
  2. Under the the VPN Tunnels tab, select the desired tunnel.
  3. Under Split Tunnel -> Application Based, make sure the type is set to 'Exclude' and add the domain 'teams.microsoft.com'.

 

add-domain-1.png

 

 

  1. Repeat step 3 for the following domains:

 

  • teams.cloud.microsoft
  • adl.windows.com
  • aka.ms
  • join.secure.skypeassets.com
  • keydelivery.mediaservices.windows.net
  • lync.com
  • mlccdnprod.azureedge.net
  • skype.com
  • streaming.mediaservices.windows.net

 

add-domain-2.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.