{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel CyberArk Identity and Privilege Cloud",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "*.cyberark.cloud",
          "purpose": "CyberArk cloud platform: user portal, Privilege Cloud and Identity",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "A *. wildcard matches subdomains of cyberark.cloud but not cyberark.cloud itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.id.cyberark.cloud",
          "purpose": "CyberArk Identity",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "A *. wildcard matches subdomains of id.cyberark.cloud but not id.cyberark.cloud itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.idaptive.app",
          "purpose": "CyberArk Identity (Idaptive platform domain)",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "A *. wildcard matches subdomains of idaptive.app but not idaptive.app itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.my.idaptive.app",
          "purpose": "CyberArk Identity (Idaptive tenant domain)",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "A *. wildcard matches subdomains of my.idaptive.app but not my.idaptive.app itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.idap.co",
          "purpose": "CyberArk Identity",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "A *. wildcard matches subdomains of idap.co but not idap.co itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.verisign.com",
          "purpose": "Certificate revocation (OCSP)",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.globalsign.com",
          "purpose": "Certificate revocation (OCSP)",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.com",
          "purpose": "Certificate revocation lists",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "secure.globalsign.com",
          "purpose": "Issuer certificates",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "privacy-policy.truste.com",
          "purpose": "Privacy policy link",
          "required": false,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#IdiraIdentityConnectorconfiguration",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "*.amazontrust.com",
          "purpose": "AWS certificate validation for Privilege Cloud (OCSP and CA issuers)",
          "required": true,
          "source": "https://docs.cyberark.com/setup/latest/en/content/ispss-deployment/deployment/deploy-outbound_traffic.htm#PrivilegeCloudconfiguration",
          "caveats": [
            "A *. wildcard matches subdomains of amazontrust.com but not amazontrust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "HTTP only: published for port 80."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}