{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Microsoft Edge",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "msedge.api.cdp.microsoft.com",
          "purpose": "Update service: checks for new Edge versions",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#update-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.dl.delivery.mp.microsoft.com",
          "purpose": "Edge and extension downloads and updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#download-locations-for-microsoft-edge",
          "caveats": [
            "A *. wildcard matches subdomains of dl.delivery.mp.microsoft.com but not dl.delivery.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "msedge.f.tlu.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTP)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#http",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "msedge.f.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTP)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#http",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "msedge.b.tlu.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTP)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#http",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "msedge.b.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTP)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#http",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "msedge.sf.tlu.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTPS)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#https",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "msedge.sf.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTPS)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#https",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "msedge.sb.tlu.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTPS)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#https",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "msedge.sb.dl.delivery.mp.microsoft.com",
          "purpose": "Edge download location (HTTPS)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#https",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.do.dsp.mp.microsoft.com",
          "purpose": "Delivery Optimization for Edge downloads (client to service)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#optionally-for-download-delivery-optimization",
          "caveats": [
            "A *. wildcard matches subdomains of do.dsp.mp.microsoft.com but not do.dsp.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "config.edge.skype.com",
          "purpose": "Experimentation and Configuration service",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#experimentation-and-configuration-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "edge.microsoft.com",
          "purpose": "Browser support services: component updates and revocation metadata, sync, cloud site list, management service, web content filtering, password monitor",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#other-browser-support-services",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.smartscreen.microsoft.com",
          "purpose": "Microsoft Defender SmartScreen",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#microsoft-defender-smartscreen-services",
          "caveats": [
            "A *. wildcard matches subdomains of smartscreen.microsoft.com but not smartscreen.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.smartscreen-prod.microsoft.com",
          "purpose": "Microsoft Defender SmartScreen",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#microsoft-defender-smartscreen-services",
          "caveats": [
            "A *. wildcard matches subdomains of smartscreen-prod.microsoft.com but not smartscreen-prod.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.urs.microsoft.com",
          "purpose": "Microsoft Defender SmartScreen",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#microsoft-defender-smartscreen-services",
          "caveats": [
            "A *. wildcard matches subdomains of urs.microsoft.com but not urs.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoft.com",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.windows.net",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.live.com",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "logincdn.msauth.net",
          "purpose": "Profile sign-in (sign-in CDN)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.microsoft.com",
          "purpose": "Profile sign-in and Purview DLP integration",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "substrate.office.com",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "odc.officeapps.live.com",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft traffic profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cdn.odc.officeapps.live.com",
          "purpose": "Profile sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft traffic profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "privacy.microsoft.com",
          "purpose": "Privacy statement during sign-in",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sign-in",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.cloudmessaging.edge.microsoft.com",
          "purpose": "Sync notifications (cloud messaging)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sync",
          "caveats": [
            "A *. wildcard matches subdomains of cloudmessaging.edge.microsoft.com but not cloudmessaging.edge.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "api.aadrm.com",
          "purpose": "Azure Information Protection for synced data",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#sync",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 73 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "clients.config.office.net",
          "purpose": "Microsoft Edge management service configuration profiles",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#microsoft-edge-management-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 47 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "edgepasskeysenclave.microsoft.com",
          "purpose": "Passkey cloud authenticator",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-endpoints#passkey-authentication",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}