Not sure if this will help, but I have identified and opened a case with Meraki Support about our MX's that we are testing 16.4 on. 16.4 is incorrectly identifying our SAP application traffic as P2P application (bittorrent), and since I have a rule that blocks all P2P applications it is getting blocked. I wonder if some of your O365 traffic is being classified as an incorrect application and being blocked by the Layer 7 firewall rules? Do you have any Layer 7 firewall rules? If so, can you disable them and see if everything starts working? If you are dumping all the MX logs to a syslog server, you can search the syslog messages for "l7_firewall" to see if you are getting traffic blocked. I dump ours in to splunk, and it shows up like this: May 5 21:46:25 10.x.x.x 1 1620265585.486264487 XXX_FW01 l7_firewall src=10.X.X.X dst=X.X.X.X protocol=tcp sport=58700 dport=3299 decision=blocked Hope it helps.
... View more