Microsoft SSO slowness or login failures through Edge SWG due to Akamai CDN block
search cancel

Microsoft SSO slowness or login failures through Edge SWG due to Akamai CDN block

book

Article ID: 446141

calendar_today

Updated On:

Products

ISG Proxy

Issue/Introduction

Users experience intermittent slowness or failures (e.g., "unable to load content") when accessing sites using Microsoft Single Sign-On (SSO) via `https://login.microsoftonline.com/`.

*   The login page hangs during the redirection flow.
*   Delays are observed
*   Proxy policy traces may show `EXCEPTION(tcp_error)` with long transaction times (~150 seconds) for CDN domains.

Environment

Edge SWG (ProxySG)
Microsoft 365 / Azure AD SSO
Upstream Firewall or Security Gateway

Cause

Microsoft authentication services rely on Content Delivery Networks (CDNs) such as Akamai to serve static files and UI components. If the upstream firewall or a security device is blacklisting akamai.com or specific Microsoft CDN IP ranges, the proxy cannot complete the TCP handshake with the destination, leading to timeouts and slowness.

Resolution

Verify connectivity to Microsoft SSO dependencies through the upstream network path.

  1. Identify the specific domains failing in the browser HAR capture or Proxy policy trace (e.g., aadcdn.msftauth.net).
  2. Perform a packet capture or tracert from the proxy to the failing destination to confirm where the drop occurs.
  3. Review upstream firewall and security device logs for blocked traffic targeting akamai.com or Microsoft-owned IP ranges.
  4. Whitelisting the blocked CDN domains on the upstream device resolves the slowness.

For more information on required Microsoft 365 endpoints, see the  documentation.

Additional Information

If you need to direct a customer specifically to a support phone number, see . Scroll to the bottom of the page and click on your respective region.