Users accessing internet sites via Cloud SWG using SEP mobile and WSS Agent users (on macOS and Windows).
All users must authenticate using SAML via MS Entra.
When looking at the access logs, the SOC team recognised that some "unauthenticated users' were allowed to access resources despite all users requring authentication. When these 'unauthenticated' entries appeared in the logs, other key fields such as WSS agent version, device names, etc are also missing.
This is not impacting their access, but the customer is concerned by the small volume of these unauthenticated requests.
Cloud SWG.
WSS Agent.
SAML Authentication.
Unauthenticated Requests Generated During Agent Tunnel Disconnect Events.
The access log entry requests showing unauthenticated users are processed by the Cloud SWG proxy immediately after the agent tunnel disconnects or moves to a different pod. It is a timing issue where the request is already out from the user's machine; however, by the time it gets to the SG, the agent tunnel is disconnected.
Fixed in May '2026 Cloud SWG update.