Known limitations

This section lists the current known limitations.

  • DCEP Mode Not Supported: Only Proxy Connect (PCEP) mode is supported for agent-based deployments.
  • FONE SSO Behavior: Single Sign-On (SSO) may use reverse proxy URL rewriting even when an agent is present.
  • Identity: For policies to apply correctly to users and groups, the end‑user identity used for Web Security Cloud and CASB must be aligned. Customers can use Data Security Cloud Identity Sync to achieve this seamlessly. Auto‑provisioning of Web Security Cloud users is disabled when Inline Proxy integration is enabled.
  • Applications:
    • When managing Microsoft applications, ensure that the O365 proxy bypass setting is not enabled in Web Security Cloud.
    • Applications or thick clients that require end‑to‑end (e2e) encryption or certificate pinning must be configured to bypass the proxy.