{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Certificate revocation and issuers",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "oneocsp.microsoft.com",
          "purpose": "OCSP for Microsoft certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.digicert.com",
          "purpose": "OCSP for DigiCert certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.digicert.cn",
          "purpose": "OCSP for DigiCert certificate authorities (China)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Looks like a certificate validation host and isn\u0027t in the Microsoft 365 list. Microsoft documents that the Entra system profile covers certificate validation but lists no hosts, so this can go either way. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl3.digicert.com",
          "purpose": "Certificate revocation lists for DigiCert certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl4.digicert.com",
          "purpose": "Certificate revocation lists for DigiCert certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl.digicert.cn",
          "purpose": "Certificate revocation lists for DigiCert certificate authorities (China)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Looks like a certificate validation host and isn\u0027t in the Microsoft 365 list. Microsoft documents that the Entra system profile covers certificate validation but lists no hosts, so this can go either way. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com",
          "purpose": "Issuer certificates (AIA) and revocation lists for Microsoft certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "caissuers.microsoft.com",
          "purpose": "Issuer certificates (AIA) for Microsoft certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "cacerts.digicert.com",
          "purpose": "Issuer certificates (AIA) for DigiCert certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "cacerts.geotrust.com",
          "purpose": "Issuer certificates (AIA) for GeoTrust certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "cacerts.digicert.cn",
          "purpose": "Issuer certificates (AIA) for DigiCert certificate authorities (China)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-certificate-authority-details#certificate-downloads-and-revocation-lists",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Looks like a certificate validation host and isn\u0027t in the Microsoft 365 list. Microsoft documents that the Entra system profile covers certificate validation but lists no hosts, so this can go either way. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl.microsoft.com",
          "purpose": "Certificate revocation lists for Microsoft certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "mscrl.microsoft.com",
          "purpose": "Certificate revocation lists for Microsoft certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.msocsp.com",
          "purpose": "OCSP for Microsoft certificate authorities",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ctldl.windowsupdate.com",
          "purpose": "Windows automatic root update and certificate trust lists, including the disallowed list",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "*.entrust.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of entrust.net but not entrust.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.geotrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of geotrust.com but not geotrust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.omniroot.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of omniroot.com but not omniroot.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.public-trust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of public-trust.com but not public-trust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.symcb.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of symcb.com but not symcb.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.symcd.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of symcd.com but not symcd.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.verisign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of verisign.com but not verisign.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.verisign.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of verisign.net but not verisign.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cert.int-x3.letsencrypt.org",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.identrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "isrg.trustid.ocsp.identrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp2.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocspx.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "secure.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com/pkiops/*",
          "purpose": "Microsoft PKI certificates and revocation lists (path-scoped alternative to www.microsoft.com)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "Wildcards in URL paths aren\u0027t documented for web filtering; a URL destination already matches its sub-paths, so drop the trailing * if the portal rejects it.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com/pki/*",
          "purpose": "Older Microsoft PKI revocation lists (path-scoped alternative to www.microsoft.com)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "Wildcards in URL paths aren\u0027t documented for web filtering; a URL destination already matches its sub-paths, so drop the trailing * if the portal rejects it.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}