> Source: [sk184811](https://support.checkpoint.com/results/sk/sk184811)

# sk184811 - Microsoft Teams disconnects when DNS Tunneling protection blocks Office 365 DNS traffic

| Property | Value |
|----------|-------|
| Solution ID | sk184811 |
| Date Created | 2026-06-23 |
| Last Modified | 2026-07-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * Users experience repeated disconnections and service disruptions in Microsoft Teams. Microsoft 365 / Teams services intermittently fail (calls drop, presence status does not update, chats do not send).

* The Security Gateway blocks DNS traffic from the internal DNS server to Microsoft 365 / Teams-related domains (for example, office.net). IPS Blade logs on the Security Gateway show **Action: Prevent** for the DNS Tunneling protection on DNS requests from the internal DNS server to Microsoft 365 / Teams domains.

* Microsoft Teams connectivity is restored only after an IPS exception is created for this traffic.

* The Security Gateway runs the Optimized Threat Prevention profile.
  The DNS Tunneling IPS protection is classified with a High severity.
  The Optimized profile is configured to Prevent IPS protections with High severity.

## Cause

The internal DNS server generates frequent and varied DNS queries to Microsoft 365 / Teams domains such as `office.net`. The traffic pattern resembles characteristics that the DNS Tunneling IPS protection detects as suspicious (for example, repeated queries and structured domain names).  

Because the DNS Tunneling protection is active in Prevent mode for High-severity protections:  

* The Security Gateway classifies these legitimate Microsoft 365 / Teams DNS queries as potential DNS tunneling.
* The IPS engine applies Prevent on these DNS queries.
* DNS resolution for Microsoft Teams and other Microsoft 365 services fails.
* The failed DNS resolution causes Microsoft Teams disconnections and service instability for users.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
