How to fully exempt Outlook Web (OWA) attachment traffic from SSL Deep Inspection
We manage a multi-branch network with FortiGates centrally managed via FortiManager, all running the same policy package. At specific branches, users attaching 2-3MB files to email through OWA (Outlook Web) experience 20-30 minute upload delays, while other branches on the identical policy are unaffected.
Our SSL/SSH Deep Inspection profile already exempts the Finance & Banking and Health & Wellness categories, plus around 20 Microsoft/Outlook-related FQDNs. We confirmed via FortiManager that this exempt list is identical across affected and unaffected branches. Setting the policy to "No Inspection" resolves the issue immediately, confirming deep inspection is the cause.
Since the exempt list is the same everywhere but the problem is branch-specific, we suspect some URLs or hostnames used by OWA for attachment upload (possibly Microsoft's Azure Front Door / M365 substrate/CDN endpoints, not just outlook.office.com) are missing from our exempt list and differ depending on branch egress/DNS path.
What is the correct and complete FQDN or wildcard list to fully exempt Outlook Web / OWA (including attachment upload/download) from SSL Deep Inspection on FortiGate? Is there an official Fortinet-maintained ISDB or FQDN group covering all M365/OWA substrate endpoints, so we don't have to rely on a manually maintained URL list that may miss edge/CDN hostnames?
Â
Â
