ERR_SSL_PROTOCOL_ERROR

anju sukumaran 0 Reputation points
2026-09-10T19:28:24.12+00:00

A few users reported that they could not access any Microsoft 365 services.

I checked Intune, and the devices were compliant. There were no sign-in logs because the connection was not reaching Microsoft. We could not sync the devices, but the date and time settings were correct. The Microsoft websites also showed a certificate security warning.

Changing the network did not resolve the issue for one user. We then allowed the affected Microsoft URL in the Defender portal. After some time, the user was asked to set up MFA again, and access was restored. The user also reported that the Microsoft Authenticator app had not been working.

Another user regained access after the same URL was allowed in Defender. A different user resolved the issue by changing their Wi-Fi network.

Around five users reported this issue on the same day, but there were no Microsoft service health alerts.

The exact cause is unclear, but it was most likely related to network or security filtering, such as Defender blocking a Microsoft URL, DNS filtering, or SSL inspection. The certificate warning and the lack of sign-in logs suggest that the connection was blocked before it reached Microsoft.

Was there any issue from Microsoft side ?

Microsoft 365 and Office | Microsoft 365 Defender | Other | Windows
0 comments No comments

1 answer

Sort by: Newest
  1. Xavier-D 12,595 Reputation points Microsoft External Staff Moderator
    2026-09-11T01:22:12.99+00:00

    Hello anju sukumaran,

    Based on the symptoms, there is not enough evidence to confirm that this was a Microsoft-side outage.

    The certificate warning, absence of Microsoft sign-in logs, and recovery after allowing the affected Microsoft URL to suggest that the connection may have been blocked or intercepted before it reached Microsoft 365.

    I recommend checking the following:

    1. In the Microsoft 365 admin center, review Health > Service health, including Issues in your environment that require action.
    2. Open Network Connectivity and check for failed Microsoft 365 domains or TLS interception insights.
    3. Confirm that your firewall, proxy, DNS filter, or security product is not performing SSL/TLS inspection on the affected Microsoft 365 endpoints.
    4. Compare the certificate shown on an affected device with one from a working device. If the certificate issuer is your security product or organization rather than Microsoft, this indicates network interception.
    5. Run the Microsoft 365 network connectivity test from an affected network and retain the results for comparison.

    Please also clarify which exact Microsoft URL was blocked, which Defender product or policy blocked it, and whether all affected users were connected through the same network, proxy, or security policy. Those details may help identify the common cause.

    I hope this helps narrow down the source of the issue.

    Feel free reply back to this post and update me on this issue, I'll be happy to help.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.