{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Microsoft Entra sign-in and admin",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Microsoft Entra sign-in and token endpoint",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoft.com",
          "purpose": "Microsoft Entra sign-in endpoint",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.windows.net",
          "purpose": "Legacy Microsoft Entra sign-in endpoint",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "device.login.microsoftonline.com",
          "purpose": "Device-based authentication for device Conditional Access",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join#network-connectivity-requirements",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "enterpriseregistration.windows.net",
          "purpose": "Device registration for Microsoft Entra join, hybrid join and device Conditional Access",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join#network-connectivity-requirements",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "autologon.microsoftazuread-sso.com",
          "purpose": "Seamless single sign-on",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join#network-connectivity-requirements",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftauth.net",
          "purpose": "Sign-in page content delivery",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msftauth.net but not msftauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msauth.net",
          "purpose": "Sign-in page content delivery",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msauth.net but not msauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftauthimages.net",
          "purpose": "Sign-in company branding images",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msftauthimages.net but not msftauthimages.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msauthimages.net",
          "purpose": "Sign-in company branding images",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msauthimages.net but not msauthimages.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftonline.com",
          "purpose": "Microsoft Entra identity service hosts",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftonline.com but not microsoftonline.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftonline-p.com",
          "purpose": "Legacy identity and sign-in content delivery",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftonline-p.com but not microsoftonline-p.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.auth.microsoft.com",
          "purpose": "Microsoft Entra authentication services, including multifactor authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of auth.microsoft.com but not auth.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msidentity.com",
          "purpose": "Microsoft Entra identity service",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msidentity.com but not msidentity.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftidentity.com",
          "purpose": "Microsoft Entra identity service",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msftidentity.com but not msftidentity.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.microsoft.com",
          "purpose": "Microsoft Graph, used by the admin centers and admin tools",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.windows.net",
          "purpose": "Legacy Azure AD Graph",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "account.activedirectory.windowsazure.com",
          "purpose": "Legacy multifactor authentication and access panel endpoint",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "passwordreset.microsoftonline.com",
          "purpose": "Self-service password reset",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "api.passwordreset.microsoftonline.com",
          "purpose": "Self-service password reset API",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.entra.microsoft.com",
          "purpose": "Microsoft Entra admin center",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/fundamentals/faq#how-can-i-allow-microsoft-entra-admin-center-urls-on-my-firewall-or-proxy-server-",
          "caveats": [
            "A *. wildcard matches subdomains of entra.microsoft.com but not entra.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "entra.microsoft.com",
          "purpose": "Microsoft Entra admin center address",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/fundamentals/faq#how-can-i-allow-microsoft-entra-admin-center-urls-on-my-firewall-or-proxy-server-",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "portal.azure.com",
          "purpose": "Azure portal address used by Entra admin center links",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.portal.azure.com",
          "purpose": "Azure portal framework shared by the Entra admin center",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of portal.azure.com but not portal.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.hosting.portal.azure.net",
          "purpose": "Azure portal extension hosting",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of hosting.portal.azure.net but not hosting.portal.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Broader than the Microsoft 365 entries it includes (such as set 73): those parts are expected to go to a Microsoft profile and the rest to Internet Access. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "hosting.portal.azure.net",
          "purpose": "Azure portal extension hosting (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.hosting-ms.portal.azure.net",
          "purpose": "Azure portal extension hosting",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of hosting-ms.portal.azure.net but not hosting-ms.portal.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "hosting-ms.portal.azure.net",
          "purpose": "Azure portal extension hosting (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.reactblade.portal.azure.net",
          "purpose": "Azure portal React blades",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of reactblade.portal.azure.net but not reactblade.portal.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "reactblade.portal.azure.net",
          "purpose": "Azure portal React blades (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "management.azure.com",
          "purpose": "Azure Resource Manager, part of the portal framework",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.ext.azure.com",
          "purpose": "Azure portal extension services",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of ext.azure.com but not ext.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ext.azure.com",
          "purpose": "Azure portal extension services (bare domain)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.graph.microsoft.com",
          "purpose": "Microsoft Graph subdomains used by the portal framework",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of graph.microsoft.com but not graph.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.graph.windows.net",
          "purpose": "Azure AD Graph subdomains used by the portal framework",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "A *. wildcard matches subdomains of graph.windows.net but not graph.windows.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "hosting.partners.azure.net",
          "purpose": "Azure portal partner extension hosting",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-framework",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "login.live.com",
          "purpose": "Microsoft account sign-in",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-authentication",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "mspim.azure.com",
          "purpose": "Privileged Identity Management",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "api.azrbac.mspim.azure.com",
          "purpose": "Privileged Identity Management API",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.aad.azure.com",
          "purpose": "Microsoft Entra portal services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of aad.azure.com but not aad.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "aad.azure.com",
          "purpose": "Microsoft Entra portal services (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ad.azure.com",
          "purpose": "Microsoft Entra portal services",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "appmanagement.activedirectory.microsoft.com",
          "purpose": "Microsoft Entra application management",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.aadconnecthealth.azure.com",
          "purpose": "Microsoft Entra Connect Health portal",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "A *. wildcard matches subdomains of aadconnecthealth.azure.com but not aadconnecthealth.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "aadconnecthealth.azure.com",
          "purpose": "Microsoft Entra Connect Health portal (bare domain)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#azure-portal-urls-for-proxy-bypass",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "identitygovernance.azure.com",
          "purpose": "Microsoft Entra ID Governance",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/azure-portal/azure-portal-safelist-urls?tabs=public-cloud#general-azure-services-and-documentation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "mysignins.microsoft.com",
          "purpose": "My Sign-ins and Security info, including MFA registration",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#switch-directory",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "myaccount.microsoft.com",
          "purpose": "My Account portal",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/identity/authentication/concept-registration-mfa-sspr-combined#set-up-security-info-from-my-account",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aka.ms",
          "purpose": "Microsoft short links such as aka.ms/mysecurityinfo",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-teams",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.microsoft.com",
          "purpose": "Certificate revocation lists",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "oneocsp.microsoft.com",
          "purpose": "OCSP for Microsoft certificates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.msocsp.com",
          "purpose": "OCSP for Microsoft certificates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "mscrl.microsoft.com",
          "purpose": "Microsoft certificate revocation list distribution",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "accounts.accesscontrol.windows.net",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "adminwebservice.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "becws.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ccs.login.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "clientconfig.microsoftonline-p.net",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "companymanager.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login-us.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline-p.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "logincert.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "loginex.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "nexus.microsoftonline-p.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "provisioningapi.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.hip.live.com",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of hip.live.com but not hip.live.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msecnd.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msecnd.net but not msecnd.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.phonefactor.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of phonefactor.net but not phonefactor.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.entrust.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of entrust.net but not entrust.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.geotrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of geotrust.com but not geotrust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.omniroot.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of omniroot.com but not omniroot.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.public-trust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of public-trust.com but not public-trust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.symcb.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of symcb.com but not symcb.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.symcd.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of symcd.com but not symcd.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.verisign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of verisign.com but not verisign.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.verisign.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of verisign.net but not verisign.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cacerts.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cert.int-x3.letsencrypt.org",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.identrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl3.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl4.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "isrg.trustid.ocsp.identrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp2.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocspx.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "secure.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}