Skip to main content
jiahoong112
Staff
Staff
March 23, 2026

Technical Tip: FortiSASE bypass for Microsoft Teams

  • March 23, 2026
  • 0 replies
  • 402 views
Description

This article describes how to configure bypass for Microsoft Teams traffic for FortiSASE SIA vpn. This is done in the endpoint profile configuration of FortiSASE.

 

Bypassing Microsoft Teams through FortiSASE is recommended as it is a high-bandwidth application: Steering Bypass Destinations.

 

Bypassing Microsoft Teams through FortiSASE VPN/Proxy is also recommended by Microsoft: Prepare your organization's network for Microsoft Teams.

Scope FortiSASE feature release.
Solution
  1. In the FortiSASE Portal, go to Endpoint Management -> Endpoint Profiles.
  2. Create or select an existing Endpoint Profile of choice. Under the Connection section, scroll down to ‘Steering bypass destinations’.
  3. Under the 'Steering bypass destinations', add the following Infrastructure and FQDN objects.

 

Infrastructure objects:

 

image.png

 

image.png

 

  • Microsoft-Teams.Published.Worldwide.Optimize.
  • Microsoft-Teams.Published.Worldwide.Allow.
  • Microsoft-Skype_Teams.
  • Microsoft-WNS.

 

Add the following FQDN objects:

  • teams.microsoft.com.
  • teams.cloud.microsoft.
  • lync.com.
  • skype.com.
  • api.flightproxy.teams.microsoft.com.
  • authsvc.teams.microsoft.com.
  • config.teams.microsoft.com.
  • devicemgmt-cdn.teams.microsoft.com.
  • api.microsoftstream.com.
  • microsoftstream.com.
  • streaming.mediaservices.windows.net.
  • teams.events.data.microsoft.com.

 

For more Microsoft Teams and Microsoft 365-related FQDNs, refer to: Technical Tip: FortiSASE SWG SSO users unable to connect/access Microsoft 365 applications Microsoft Teams, Outlook

Microsoft Teams IP Range and URLs

 

Note: Some IPs may belong to other ISDB objects such as 'Akamai-CDN'. When this happens, traffic to those specific destinations may still pass through the VPN tunnel to FortiSASE.