Unauthenticated users randomly seem on WSS Agent tenant
search cancel

Unauthenticated users randomly seem on WSS Agent tenant

book

Article ID: 442771

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Users accessing internet sites via Cloud SWG using SEP mobile and WSS Agent users (on macOS and Windows).

All users must authenticate using SAML via MS Entra.

When looking at the access logs, the SOC team recognised that some "unauthenticated users' were allowed to access resources despite all users requring authentication. When these 'unauthenticated' entries appeared in the logs, other key fields such as WSS agent version, device names, etc are also missing.

This is not impacting their access, but the customer is concerned by the small volume of these unauthenticated requests.

Environment

Cloud SWG.

WSS Agent.

SAML Authentication.

Cause

Unauthenticated Requests Generated During Agent Tunnel Disconnect Events.

The access log entry requests showing unauthenticated users are processed by the Cloud SWG proxy immediately after the agent tunnel disconnects or moves to a different pod. It is a timing issue where the request is already out from the user's machine; however, by the time it gets to the SG, the agent tunnel is disconnected. 

Resolution

Fixed in May '2026 Cloud SWG update.