We had UDP listed as DNS Sec uses UDP 443. We moved the alert prio so TCP traffic is evaluated first but I dont think that will matter since they are two different streams and dont match as TCP and UDP traffic is seen differently. We were able to use this MS article to whitelist the addresses needed and now attempting to do one off service troubleshooting. Microsoft 365 URLs and IP address ranges - Microsoft 365 Enterprise | Microsoft Learn There is a JSON in this that we parsed with all MS service URLS I believe that we got this to work however will be testing further towards the end of this week. If its solved Ill make sure to give you credit! Cant thank you enough for your help thus far!
... View more