Is the "*.mcas.ms" URL redirected to the original site by default?

임우협 20 Reputation points
2023-02-16T05:41:52.16+00:00

I recently found a URL called "https://login.microsoft.com.mcas-df-gov.us" and it redirect me to "https://login.microsoft.com".
And after doing some google, I found two documents.

I have found that the above domains (*.mcas.ms, mcas-df-gov.ms, etc.) are used by a feature(Conditional Access App Control) of Microsoft Defender for Cloud Apps.

It exists between cloud apps and clients and is understood as a product that detects security threats in packets sent and received by cloud apps and clients.

In addition, if a client create a session on a website protected by the Microsoft Defender, all relevant URLs and cookies will be *.It ends with mcas.ms.

https://learn.microsoft.com/en-us/defender-cloud-apps/proxy-intro-aad#how-session-control-works

So, back to the main point, when I went to the URL "https://login.microsoft.com.mcas-df-gov.us/", I was redirected to "login.microsoft.com" because I sent the request directly without creating the session?

Plus) is default redirect a feature that will continue to be maintained in the future?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2023-02-21T07:08:48.6533333+00:00

    @임우협 Apologies for the delay in reviewing this post, yes your understanding is correct related to this question, you accessed the below url without login, as the session is not protected by defender for cloud apps, the same has been mentioned in this article which has been shared by you in the query.

    when I went to the URL "https://login.microsoft.com.mcas-df-gov.us/", I was redirected to "login.microsoft.com" because I sent the request directly without creating the session?

    Regarding the other query, redirect feature will continue to be maintained by defender for cloud apps.

    Would like to share couple of links related to defender for cloud apps:

    https://www.youtube.com/watch?v=IG5VglS_sOo

    https://www.youtube.com/watch?v=O69Td1BoY80&list=PLmAptfqzxVEWPdYnWAM9ZIr81jWESvPTN

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.