MicrosoftDocs / CloudAppSecurityDocs

Public repo for CloudAppSecurityDocs-pr

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Conditional Access App Control reverse proxy architecture and Context loss with Sharepoint

saif-chaudhry opened this issue · comments

In the known limitations section of the document https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad#known-limitations

The document discuss about "Context loss" but doesn't list Microsoft Sharepoint product. Can you help explain how this doesn't effect Sharepoint? How the solution handles the "Context" when it is using ReverseProxy architecture with Sharepoint? Consider this;

  • Reverse Proxy solution is based on rewrite of the domains.
  • On Sharepoint links the context of the link is stored on cookie with the domain.
  • When a managed user shares the sharepoint link(non rewritten) to a unmanaged user, the user will be redirected to reverseproxy domain during login.
  • When the domain switch happens the cookies set on original Sharepoint link is lost in transition to the rewritten domain as browser see that for the new domain there is no cookies and the cookies will not be sent to MS and MS does not know where to land the user and lands the user to Sharepoint homepage instead of the page.

Some clarification on how this works is appreciated.

Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

Thank you for your comment. We'll investigate and get back to you.

@saif-chaudhry The product group has informed me that there is no evidence of context loss with SharePoint. If you still have an issue in this regard, we recommend you open a support case. Thank you.