logo
search
Conditional Access Problems

How to Prevent MCAS from Removing Authentication Headers

Elise WilliamsElise Williams Oct 10, 2026 868 views

Question details

The user needs to prevent MCAS from stripping the Authentication header during redirection from InPrivate sessions or unsupported devices.

How to Prevent MCAS from Removing Authentication Headers
Product
Microsoft Cloud App Security (MCAS)
Device & OS
not provided
Scenario
Accessing an Azure App Service application through a Microsoft Cloud App Security (MCAS) conditional access policy.
Observed behavior
Requests reach the Azure App Service without MSAL credentials, returning a 401 unauthorized error due to stripped authentication headers.
Before you start

Gather your current MCAS policy settings, redirect behavior logs, request headers, and Azure App Service authentication configuration before seeking enterprise support.

Solution 1Recommended

Escalate the Issue to Microsoft Q&A Enterprise Support

Since MCAS and Azure App Service are enterprise-level products, consumer support channels cannot resolve configuration or policy issues related to header stripping.

Microsoft Cloud App Security (now Microsoft Defender for Cloud Apps) acting as a reverse proxy for Conditional Access App Control can sometimes modify or drop specific headers. Because adjusting these policies requires tenant-level administrative access and enterprise-grade troubleshooting, this issue must be directed to specialized Microsoft engineers.

1
Navigate to Microsoft Q&A

Open your web browser and go to the official Microsoft Q&A platform at https://learn.microsoft.com/en-us/answers/.

2
Prepare your environment details

Compile relevant technical details including your specific MCAS policy, network trace of request headers, redirect behavior logs, and your Azure App Service authentication configuration.

3
Post a new question

Submit your detailed query using tags like 'Azure Active Directory' and 'Microsoft Defender for Cloud Apps' to ensure it reaches qualified enterprise support engineers.

Escalate the Issue to Microsoft Q&A Enterprise Support
Enterprise Support Required: Standard community forums do not have the necessary tools or access to troubleshoot enterprise conditional access and MCAS proxy policies.
Free Microsoft Office alternative

Looking for a Reliable and Free Office Suite for Your Business?

While you troubleshoot enterprise Azure configurations, ensure your team stays productive with WPS Office. It provides a lightweight, comprehensive, and highly compatible alternative to Microsoft Office without the heavy licensing costs.

  1. 1. Download WPS Office: Visit the official WPS website and click the free download button.
  2. 2. Install the application: Run the downloaded installer and follow the on-screen instructions to set up the software.
  3. 3. Start working instantly: Open your existing Microsoft Office documents in WPS Office and begin editing without any format conversion issues.
Fully compatible with Microsoft Word, Excel, and PowerPoint formatsLightweight installation with fast document processingFamiliar user interface requires no retraining for your teamIncludes built-in advanced PDF editing and collaboration tools
microsoft office alternative - wps office

Frequently Asked Questions

Why does MCAS remove the Authentication header?

MCAS acts as a reverse proxy for Conditional Access App Control. When handling sessions from unsupported devices or InPrivate browsing, it may strip certain headers for security reasons or due to custom session control policies configured by your organization.

What causes the 401 error in Azure App Service?

The 401 Unauthorized error occurs because the Azure App Service expects valid MSAL credentials (like a bearer token) in the Authorization header. When the MCAS proxy strips this header during a redirect, the application cannot authenticate the incoming request.

Can I fix this issue in standard consumer support forums?

No. Microsoft Cloud App Security and Azure App Service are enterprise-grade products. Issues involving conditional access policies require specialized knowledge and should be posted on the Microsoft Q&A enterprise forums.

How can I trace the missing authentication headers?

You can use browser developer tools (F12) to inspect the network requests, or use debugging tools like Fiddler, HTTP Toolkit, or Azure Application Insights to capture the request headers before and after the MCAS redirect.