The Lync team has recently discovered additional steps for Lync Online admins to take to ensure smooth service performance. This applies to Lync Online tenants, and hybrid deployments where some users are homed in Lync Online after being moved from a Lync Server on-premises deployment.

As a result of the recent acquisition of Verisign by Symantec, you’ll need to add this new certificate revocation list (CRL) endpoint to your list of allowed locations:

 

Location

Protocols

sa.symcb.com

Outgoing TLS and HTTPS

 

Add this new rule to your firewall or proxy server to avoid Lync sign-in issues and ensure a secure connection to Office 365.  

IMPORTANT: You must add this allowed CRL endpoint to any device that is filtering web traffic: firewalls, load balancers, proxy servers, web security software/appliances, and so on.

 
See also

Lync Online URLs and IP Address Ranges

Set up your network for Lync Online