How to Prevent MCAS from Removing Authentication Headers
Question details
The user needs to prevent MCAS from stripping the Authentication header during redirection from InPrivate sessions or unsupported devices.

- Product
- Microsoft Cloud App Security (MCAS)
- Device & OS
- not provided
- Scenario
- Accessing an Azure App Service application through a Microsoft Cloud App Security (MCAS) conditional access policy.
- Observed behavior
- Requests reach the Azure App Service without MSAL credentials, returning a 401 unauthorized error due to stripped authentication headers.
Gather your current MCAS policy settings, redirect behavior logs, request headers, and Azure App Service authentication configuration before seeking enterprise support.
Escalate the Issue to Microsoft Q&A Enterprise Support
Since MCAS and Azure App Service are enterprise-level products, consumer support channels cannot resolve configuration or policy issues related to header stripping.
Microsoft Cloud App Security (now Microsoft Defender for Cloud Apps) acting as a reverse proxy for Conditional Access App Control can sometimes modify or drop specific headers. Because adjusting these policies requires tenant-level administrative access and enterprise-grade troubleshooting, this issue must be directed to specialized Microsoft engineers.
Open your web browser and go to the official Microsoft Q&A platform at https://learn.microsoft.com/en-us/answers/.
Compile relevant technical details including your specific MCAS policy, network trace of request headers, redirect behavior logs, and your Azure App Service authentication configuration.
Submit your detailed query using tags like 'Azure Active Directory' and 'Microsoft Defender for Cloud Apps' to ensure it reaches qualified enterprise support engineers.

Looking for a Reliable and Free Office Suite for Your Business?
While you troubleshoot enterprise Azure configurations, ensure your team stays productive with WPS Office. It provides a lightweight, comprehensive, and highly compatible alternative to Microsoft Office without the heavy licensing costs.
- 1. Download WPS Office: Visit the official WPS website and click the free download button.
- 2. Install the application: Run the downloaded installer and follow the on-screen instructions to set up the software.
- 3. Start working instantly: Open your existing Microsoft Office documents in WPS Office and begin editing without any format conversion issues.

Frequently Asked Questions
Why does MCAS remove the Authentication header?
MCAS acts as a reverse proxy for Conditional Access App Control. When handling sessions from unsupported devices or InPrivate browsing, it may strip certain headers for security reasons or due to custom session control policies configured by your organization.
What causes the 401 error in Azure App Service?
The 401 Unauthorized error occurs because the Azure App Service expects valid MSAL credentials (like a bearer token) in the Authorization header. When the MCAS proxy strips this header during a redirect, the application cannot authenticate the incoming request.
Can I fix this issue in standard consumer support forums?
No. Microsoft Cloud App Security and Azure App Service are enterprise-grade products. Issues involving conditional access policies require specialized knowledge and should be posted on the Microsoft Q&A enterprise forums.
How can I trace the missing authentication headers?
You can use browser developer tools (F12) to inspect the network requests, or use debugging tools like Fiddler, HTTP Toolkit, or Azure Application Insights to capture the request headers before and after the MCAS redirect.




