{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Defender for Endpoint (streamlined)",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "*.endpoint.security.microsoft.com",
          "purpose": "Consolidated core MDE services: cloud-delivered protection (MAPS), sample submission and AutoIR storage, command and control, cyber/diagnostic data",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/configure-device-connectivity#option-1-configure-connectivity-using-the-simplified-domain",
          "caveats": [
            "A *. wildcard matches subdomains of endpoint.security.microsoft.com but not endpoint.security.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.smartscreen-prod.microsoft.com",
          "purpose": "SmartScreen browsing protection, network/web protection, web content filtering, custom URL/IP indicators",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-core-functionality",
          "caveats": [
            "A *. wildcard matches subdomains of smartscreen-prod.microsoft.com but not smartscreen-prod.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.smartscreen.microsoft.com",
          "purpose": "SmartScreen web/network protection and app-execution reputation",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-core-functionality",
          "caveats": [
            "A *. wildcard matches subdomains of smartscreen.microsoft.com but not smartscreen.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.checkappexec.microsoft.com",
          "purpose": "SmartScreen check of application execution for trusted apps",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-core-functionality",
          "caveats": [
            "A *. wildcard matches subdomains of checkappexec.microsoft.com but not checkappexec.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.urs.microsoft.com",
          "purpose": "SmartScreen application reputation",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-core-functionality",
          "caveats": [
            "A *. wildcard matches subdomains of urs.microsoft.com but not urs.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "reflector.defender.microsoft.com",
          "purpose": "Defender IPv6 connectivity probe",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-core-functionality",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "go.microsoft.com",
          "purpose": "Defender Antivirus CDN: security intelligence and platform updates (MMPC alternative/fallback)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "definitionupdates.microsoft.com",
          "purpose": "Defender Antivirus security intelligence and platform update CDN",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.update.microsoft.com",
          "purpose": "Windows Update source for security intelligence, platform and EDR sensor updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "A *. wildcard matches subdomains of update.microsoft.com but not update.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.delivery.mp.microsoft.com",
          "purpose": "Windows Update delivery for Defender updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "A *. wildcard matches subdomains of delivery.mp.microsoft.com but not delivery.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.windowsupdate.com",
          "purpose": "Windows Update delivery for Defender updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "A *. wildcard matches subdomains of windowsupdate.com but not windowsupdate.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.download.windowsupdate.com",
          "purpose": "Windows Update download for Defender updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "A *. wildcard matches subdomains of download.windowsupdate.com but not download.windowsupdate.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.download.microsoft.com",
          "purpose": "Microsoft download CDN for Defender updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "A *. wildcard matches subdomains of download.microsoft.com but not download.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ctldl.windowsupdate.com",
          "purpose": "Automatic root update / certificate trust list; flags compromised certificates as untrusted",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl.microsoft.com",
          "purpose": "Certificate revocation lists for certificate validation",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Live Response push notifications (WNS) and Entra sign-in to the Defender portal",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#additional-service-urls",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.wns.windows.com",
          "purpose": "Windows Push Notification Services for Live Response",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#additional-service-urls",
          "caveats": [
            "A *. wildcard matches subdomains of wns.windows.com but not wns.windows.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 SharePoint endpoint set 35 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.live.com",
          "purpose": "Live Response push notification model",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#additional-service-urls",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "https://www.microsoft.com/security/encyclopedia/adlpackages.aspx",
          "purpose": "Defender Antivirus update package location (MMPC)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-updates",
          "caveats": [
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com/pkiops/*",
          "purpose": "Certificate revocation list updates used when creating the SSL connection to MAPS",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "Wildcards in URL paths aren\u0027t documented for web filtering; a URL destination already matches its sub-paths, so drop the trailing * if the portal rejects it.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com/pki/*",
          "purpose": "Certificate revocation list updates (Windows certificate validation)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/defender-endpoint/streamlined-device-connectivity-urls-commercial#urls-used-for-certificate-validation-checks",
          "caveats": [
            "Wildcards in URL paths aren\u0027t documented for web filtering; a URL destination already matches its sub-paths, so drop the trailing * if the portal rejects it.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}