182/182 feeds/APIs · 190/193 docs · synced 03:08 UTC Customize Public mode

Access bundles

What a locked-down admin workstation or managed device has to reach, one job at a time, with every destination traced to the page that publishes it. Download a bundle as a plain list or in Global Secure Access web filtering formats.

Admin workstation Microsoft Entra sign-in and admin Sign in to Microsoft Entra ID, use the Entra admin center and Microsoft Graph, and register security info for MFA. 107 destinations 20 expected at web filtering 48 probably taken first7 curatedReviewed 6 Oct 2026Admin workstation Microsoft 365 admin portals Reach the Microsoft 365, Exchange, SharePoint, Teams, Defender, Purview and Intune admin centers. Use with the Entra sign-in bundle. 29 destinations 0 expected at web filtering 10 probably taken first1 curatedReviewed 6 Oct 2026Admin workstation Azure portal The Azure portal safelist for the public cloud: authentication, the portal framework, account data, and optional per-service hosts. 109 destinations 81 expected at web filtering 15 probably taken first24 curatedReviewed 6 Oct 2026Managed device Defender for Endpoint (streamlined) Streamlined device connectivity for Microsoft Defender for Endpoint on Windows, with the update, certificate validation, SmartScreen and Live Response hosts. 21 destinations 0 expected at web filtering 1 probably taken firstReviewed 6 Oct 2026Managed device Global Secure Access client What the Global Secure Access client itself needs: its service edges, health probes and the sign-in it relies on. Exclude these from any other proxy. 26 destinations 8 expected at web filtering 1 probably taken first2 curatedReviewed 6 Oct 2026Admin workstation PowerShell modules and admin sign-in Install and update modules from the PowerShell Gallery, then sign in with Microsoft Graph PowerShell, Microsoft Entra PowerShell or Exchange Online PowerShell. 11 destinations 4 expected at web filtering 4 probably taken firstReviewed 6 Oct 2026Admin workstation Okta sign-in Reach your Okta org for sign-in, the dashboard and Okta Verify, with the Okta CDN and the region-specific Okta domains. 20 destinations 17 expected at web filtering 0 probably taken first1 curatedReviewed 6 Oct 2026Managed device Intune-managed Windows devices The Intune admin center plus what managed Windows devices need: enrollment and check-in, Win32 app and script delivery, push notifications, Autopilot, attestation, the Store API and optional Remote Help. 227 destinations 40 expected at web filtering 89 probably taken firstReviewed 6 Oct 2026Managed device Windows Update and Microsoft Store Windows Update, Delivery Optimization and the Microsoft Store for managed Windows devices, with optional Windows Autopatch hosts. 32 destinations 2 expected at web filtering 1 probably taken firstReviewed 6 Oct 2026Managed device Windows 365 and Azure Virtual Desktop What an end-user device needs to connect to Cloud PCs and Azure Virtual Desktop sessions with Windows App, the Remote Desktop clients or the web client. The Cloud PCs and session hosts have their own, longer list. 95 destinations 4 expected at web filtering 48 probably taken firstReviewed 6 Oct 2026Managed device Certificate revocation and issuers Revocation (CRL and OCSP) and issuer (AIA) hosts for the certificate authorities behind Microsoft's services. Blocked revocation checks make TLS clients either refuse the connection or wait for timeouts before giving up, so sign-ins, updates and agents fail or slow down. 35 destinations 0 expected at web filtering 0 probably taken firstReviewed 6 Oct 2026Managed device Microsoft Edge Microsoft Edge updates, configuration, profile sign-in, sync and SmartScreen on a managed device. 30 destinations 0 expected at web filtering 5 probably taken firstReviewed 6 Oct 2026Admin workstation CyberArk Identity and Privilege Cloud Reach the CyberArk Identity sign-in and the Privilege Cloud portal from an admin workstation, with the certificate checks they rely on. 15 destinations 11 expected at web filtering 0 probably taken first1 curatedReviewed 6 Oct 2026

Global Secure Access web filtering: V1 and V2

What decides whether a destination gets through
  1. Which profile takes it? GSA checks the always-on Microsoft Entra system profile (sign-in, Graph, certificate validation) and the Microsoft traffic profile (built from the Microsoft 365 endpoint list) before Internet Access. Microsoft documents that traffic the Microsoft traffic profile can acquire is acquired only there, even when a rule is set to Bypass. It publishes neither profile's host list, so bundles show how strongly the public material supports each call, and none of it is confirmed. Your tenant's real rules are in the GSA client: Advanced diagnostics, Forwarding profile.
  2. V2 runs first. A V2 Block is final. A V2 Allow is not: the request then goes to V1.
  3. V1 runs second and can still block what V2 allowed, including from a lower-priority profile. A destination that is allowed in V2 but still blocked usually has a V1 policy in the way.
  4. V2 matching is broader. A V1 domain rule matched the host; the same domain as a V2 URL destination matches the address and its paths.
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 03:08 UTC · 182 of 182 readable · documentation 190/193 current