It's not a 'feature'. It's a traffic routing bypass that gets misconfigured constantly.
Prisma Access usually tunnels all your user traffic to a Prisma data center for inspection. Local Breakout for O365 creates an exception. It matches traffic to Microsoft's published IP ranges and lets it go directly from the user's location to the nearest Microsoft front door.
* Your user in London connects to Prisma.
* Their Teams call hits a rule matching Microsoft's IPs.
* Instead of going to Prisma's nearest node (maybe Frankfurt), the traffic exits locally in London straight to Microsoft.
The critical part is the policy. It's not magic. You define it with Service Connections and Security Policy rules. A common mistake is using too-broad FQDN objects.
```xml
Internal-User-Group
MS-365-IPs
ms-office-365
application-default
allow
any
any
```
You are trusting Microsoft's network. That traffic bypasses most of Prisma's inspection stack. Get the destination lists wrong and you're punching holes in your security.
Least privilege is not a suggestion.