Hello Guys,
well i see NO reason to change any rules, because the policy matching, or lets say, which Updateable Object the FW chooses for policy matching is changing from session to session.
take a look:
my logging resulsts, during a MS teams call.
SRC: 10.10.42.68 and DST: 52.113.83.112
sometimes accept, sometimes drop.

fist the accept, it matches on MS Teams ...

then the drop:
same SRC & same DST. just new SRC port, so lets say a new connection ...
but is says Github this time ...

lets see what TAC can do here, since the firewall changes its match on the DST IP from time to time.