Why do cloud services work outside the office but not inside the network or VPN?

When a cloud service works on another network, the cause may be DNS, a proxy, firewall rules, TLS inspection, routing or VPN full tunneling. Compare name resolution, connectivity and device time without permanently disabling protections. Cloud platforms change addresses and destinations, so rigid or outdated rules can fail.

Risks to review

  • Disable firewall, antivirus or inspection as a permanent shortcut.
  • Allow excessive address ranges without identifying the required traffic.
  • Use different DNS services inside and outside the VPN without documenting them.
  • Confuse a provider outage with a local network failure.

Safe recommendations

  1. Compare the same equipment inside and outside the affected network.
  2. Record service, URL, time, error and if resolution or connection fails.
  3. Review DNS, proxy, routes, and firewall logs before creating exceptions.
  4. Check date, certificates and TLS inspection.
  5. Use the supplier's current destination documentation.
  6. Apply minimal changes and confirm that they do not reduce overall protection.

When to seek specialized help

  • The failure affects an entire site or VPN users.
  • Only works when disabling security controls.
  • There are duplicate routes, internal DNS, or multiple Internet links.

Reference sources

These public sources provide general good-practice guidance. They do not replace an assessment of your environment.