Unable to connect to www.msftconnecttest.com when WSS Agent is active
search cancel

Unable to connect to www.msftconnecttest.com when WSS Agent is active


Article ID: 248622


Updated On:


Cloud Secure Web Gateway - Cloud SWG


When the WSS agent was active, connections to the www.msftconnecttest.com domain were failing.

The network packet capture showed that the request was bypassing the WSS agent.

The WSS portal 'Bypassed Traffic' section did not have an IP/Domain bypass added for the domain.


Windows 10 and later.

WSS Agent 7.1.1 and later.


The WSS Agent always bypasses the following domains regardless of tenant configuration or bypass list:

  • www.msftconnecttest.com
  • dns.msftncsi.com
  • ipv6.msftconnecttest.com

The web requests to these domains cannot be sent via the WSS agent tunnel because it would interfere with the Windows network discovery mechanism (NCSI service) and disrupt WSS agent connectivity logic.


  • Access to these NCSI domains should be set to behave as required by your organization's network requirement. The purpose of these domains is that they should be treated as 'normal' default traffic.
  • There is no requirement for the WSS Agent to function properly to have any special network rules applied to these NCSI probe domains.


Additional Information

An Internet Explorer or Edge window opens when your computer connects to a corporate network or a public network