> Source: [sk165995](https://support.checkpoint.com/results/sk/sk165995)

# sk165995 - Office365 Updatable object allowing additional domain 

| Property | Value |
|----------|-------|
| Solution ID | sk165995 |
| Date Created | 2020-03-25 |
| Last Modified | 2020-05-12 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- when using "office365 Services" updatable object in a policy rule, the traffic to Facebook also matches this rule. Access to Facebook should not be possible using the O365 updatable object.

## Cause

The "office365 services" updatable object includes several other updatable objects.   
One of them is "office365 Third Party Domains" and this includes all 3rd party domains with Microsoft.   

facebook.com is one of the domains in the 3rd party domain list.  

To review the full list of 3rd party domains, run the following command on the gateway that enforces the services object:  

**Note that, this list is dynamic updated by Microsoft.**   

*# domains_tool -uo "Office365 Third Party Domains"*

<br />

## Solution

Add another rule to block office365 3rd party update objects on top of the allow rules.  

1. Check the log to find out which domain is allowed by the "office365 services" updatable object.
2. Find the URL object, or create a domain object for that one.
3. Use the new object and setup a block rule for it.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
