I captured traffic on a win10 client that is joined to a AzureAD I want to filter for the AzureAD authentication. ip.addr = x.x.x.x and keberos works for on prem AD. How to filter for Azure AD authenication?

Can you explain more about the client connection. Is it using this which is an encrypted connection over port 443?

Chuckc gravatar imageChuckc ( 2020-09-03 14:48:32 +0000 )edit