{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Azure portal",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "portal.azure.com",
          "purpose": "Portal apex (non-wildcard companion of *.portal.azure.com)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoft.com",
          "purpose": "Azure portal authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Azure portal authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.live.com",
          "purpose": "Azure portal authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.aadcdn.msftauth.net",
          "purpose": "Azure portal authentication (sign-in CDN)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of aadcdn.msftauth.net but not aadcdn.msftauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aadcdn.msftauth.net",
          "purpose": "Azure portal authentication (sign-in CDN) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.aadcdn.msftauthimages.net",
          "purpose": "Azure portal authentication (branding images CDN)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of aadcdn.msftauthimages.net but not aadcdn.msftauthimages.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aadcdn.msftauthimages.net",
          "purpose": "Azure portal authentication (branding images CDN) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.aadcdn.msauthimages.net",
          "purpose": "Azure portal authentication (branding images CDN)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of aadcdn.msauthimages.net but not aadcdn.msauthimages.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aadcdn.msauthimages.net",
          "purpose": "Azure portal authentication (branding images CDN) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.logincdn.msftauth.net",
          "purpose": "Azure portal authentication (login CDN)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of logincdn.msftauth.net but not logincdn.msftauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "logincdn.msftauth.net",
          "purpose": "Azure portal authentication (login CDN) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msauth.net",
          "purpose": "Azure portal authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of msauth.net but not msauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "msauth.net",
          "purpose": "Azure portal authentication (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.aadcdn.microsoftonline-p.com",
          "purpose": "Azure portal authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of aadcdn.microsoftonline-p.com but not aadcdn.microsoftonline-p.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aadcdn.microsoftonline-p.com",
          "purpose": "Azure portal authentication (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftonline-p.com",
          "purpose": "Azure portal authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftonline-p.com but not microsoftonline-p.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "microsoftonline-p.com",
          "purpose": "Azure portal authentication (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.portal.azure.com",
          "purpose": "Azure portal framework",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of portal.azure.com but not portal.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.hosting.portal.azure.net",
          "purpose": "Azure portal framework (extension hosting)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of hosting.portal.azure.net but not hosting.portal.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Broader than the Microsoft 365 entries it includes (such as set 73): those parts are expected to go to a Microsoft profile and the rest to Internet Access. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "hosting.portal.azure.net",
          "purpose": "Azure portal framework (extension hosting) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.hosting-ms.portal.azure.net",
          "purpose": "Azure portal framework (extension hosting)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of hosting-ms.portal.azure.net but not hosting-ms.portal.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "hosting-ms.portal.azure.net",
          "purpose": "Azure portal framework (extension hosting) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.reactblade.portal.azure.net",
          "purpose": "Azure portal framework (React blades)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of reactblade.portal.azure.net but not reactblade.portal.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "reactblade.portal.azure.net",
          "purpose": "Azure portal framework (React blades) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "management.azure.com",
          "purpose": "Azure portal framework (Azure Resource Manager)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.ext.azure.com",
          "purpose": "Azure portal framework (extensions)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of ext.azure.com but not ext.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ext.azure.com",
          "purpose": "Azure portal framework (extensions) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.graph.windows.net",
          "purpose": "Azure portal framework (Azure AD Graph)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of graph.windows.net but not graph.windows.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "graph.windows.net",
          "purpose": "Azure portal framework (Azure AD Graph) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.graph.microsoft.com",
          "purpose": "Azure portal framework (Microsoft Graph)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of graph.microsoft.com but not graph.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.microsoft.com",
          "purpose": "Azure portal framework (Microsoft Graph) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "hosting.partners.azure.net",
          "purpose": "Azure portal framework (partner extension hosting)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.account.microsoft.com",
          "purpose": "Account data",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data",
          "caveats": [
            "A *. wildcard matches subdomains of account.microsoft.com but not account.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "account.microsoft.com",
          "purpose": "Account data (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.bmx.azure.com",
          "purpose": "Account data",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data",
          "caveats": [
            "A *. wildcard matches subdomains of bmx.azure.com but not bmx.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "bmx.azure.com",
          "purpose": "Account data (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.subscriptionrp.trafficmanager.net",
          "purpose": "Account data (subscriptions)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data",
          "caveats": [
            "A *. wildcard matches subdomains of subscriptionrp.trafficmanager.net but not subscriptionrp.trafficmanager.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "subscriptionrp.trafficmanager.net",
          "purpose": "Account data (subscriptions) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.signup.azure.com",
          "purpose": "Account data (sign-up)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#account-data",
          "caveats": [
            "A *. wildcard matches subdomains of signup.azure.com but not signup.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "signup.azure.com",
          "purpose": "Account data (sign-up) (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "aka.ms",
          "purpose": "Microsoft short URL",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.asazure.windows.net",
          "purpose": "Analysis Services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of asazure.windows.net but not asazure.windows.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.azconfig.io",
          "purpose": "AzConfig Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of azconfig.io but not azconfig.io itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "azconfig.io",
          "purpose": "AzConfig Service (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.aad.azure.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of aad.azure.com but not aad.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "aad.azure.com",
          "purpose": "Microsoft Entra (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.aadconnecthealth.azure.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of aadconnecthealth.azure.com but not aadconnecthealth.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "aadconnecthealth.azure.com",
          "purpose": "Microsoft Entra (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ad.azure.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "adf.azure.com",
          "purpose": "Azure Data Factory",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "api.aadrm.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 73 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "api.loganalytics.io",
          "purpose": "Log Analytics Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "api.azrbac.mspim.azure.com",
          "purpose": "Microsoft Entra (PIM)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.applicationinsights.azure.com",
          "purpose": "Application Insights Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of applicationinsights.azure.com but not applicationinsights.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "applicationinsights.azure.com",
          "purpose": "Application Insights Service (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "appmanagement.activedirectory.microsoft.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "appservice.azure.com",
          "purpose": "Azure App Services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.arc.azure.net",
          "purpose": "Azure Arc",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of arc.azure.net but not arc.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "arc.azure.net",
          "purpose": "Azure Arc (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "asazure.windows.net",
          "purpose": "Analysis Services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "bastion.azure.com",
          "purpose": "Azure Bastion Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "batch.azure.com",
          "purpose": "Azure Batch Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "catalogapi.azure.com",
          "purpose": "Azure Marketplace",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "catalogartifact.azureedge.net",
          "purpose": "Azure Marketplace",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "changeanalysis.azure.com",
          "purpose": "Change Analysis",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "cognitiveservices.azure.com",
          "purpose": "Cognitive Services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "config.office.com",
          "purpose": "Microsoft Office",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cosmos.azure.com",
          "purpose": "Azure Cosmos DB",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.database.windows.net",
          "purpose": "SQL Server",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of database.windows.net but not database.windows.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "database.windows.net",
          "purpose": "SQL Server (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "datalake.azure.net",
          "purpose": "Azure Data Lake Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "dev.azure.com",
          "purpose": "Azure DevOps",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "dev.azuresynapse.net",
          "purpose": "Azure Synapse",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "digitaltwins.azure.net",
          "purpose": "Azure Digital Twins",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "elm.iga.azure.com",
          "purpose": "Microsoft Entra (entitlement management)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "eventhubs.azure.net",
          "purpose": "Azure Event Hubs",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "functions.azure.com",
          "purpose": "Azure Functions",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "gallery.azure.com",
          "purpose": "Azure Marketplace",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "go.microsoft.com",
          "purpose": "Microsoft documentation placeholder",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "help.kusto.windows.net",
          "purpose": "Azure Kusto Cluster Help",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "identitygovernance.azure.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "iga.azure.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "informationprotection.azure.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "kusto.windows.net",
          "purpose": "Azure Kusto Clusters",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "learn.microsoft.com",
          "purpose": "Azure documentation",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "logic.azure.com",
          "purpose": "Logic Apps",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "marketplacedataprovider.azure.com",
          "purpose": "Azure Marketplace",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "main.prod.marketplacedataprovider.azure.com",
          "purpose": "Azure Marketplace",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "marketplaceemail.azure.com",
          "purpose": "Azure Marketplace",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "media.azure.net",
          "purpose": "Azure Media Services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "monitor.azure.com",
          "purpose": "Azure Monitor Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.msidentity.com",
          "purpose": "Microsoft Entra",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of msidentity.com but not msidentity.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "msidentity.com",
          "purpose": "Microsoft Entra (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "mspim.azure.com",
          "purpose": "Microsoft Entra (PIM)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "network.azure.com",
          "purpose": "Azure Network",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "purview.azure.com",
          "purpose": "Azure Purview",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "quantum.azure.com",
          "purpose": "Azure Quantum Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "rest.media.azure.net",
          "purpose": "Azure Media Services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "search.azure.com",
          "purpose": "Azure Search",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "servicebus.azure.net",
          "purpose": "Azure Service Bus",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "servicebus.windows.net",
          "purpose": "Azure Service Bus",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "shell.azure.com",
          "purpose": "Azure Command Shell",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "sphere.azure.net",
          "purpose": "Azure Sphere",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "azure.status.microsoft",
          "purpose": "Azure Status",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "storage.azure.com",
          "purpose": "Azure Storage",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "storage.azure.net",
          "purpose": "Azure Storage",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "vault.azure.net",
          "purpose": "Azure Key Vault Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ux.console.azure.com",
          "purpose": "Azure Cloud Shell",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}