Your work is likely blocking the domains they use for authentication, but once you're registered and got the peer IP and port, once you're back on WiFi the corporate firewall doesn't catch that.
A lot of VPNs just log in over an HTTPS API which isn't exactly stealthy.