182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Global Secure Access client

What the Global Secure Access client itself needs: its service edges, health probes and the sign-in it relies on. Exclude these from any other proxy.

Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Global Secure Access

Microsoft publishes these service FQDNs and IP ranges as bypass lists on its SSE coexistence pages; there is no standalone network requirements page. Replace <tenantid> with your tenant ID. The client needs secure DNS (DoH/DoT) disabled, tunnels IPv4 only, and does not tunnel QUIC for Internet Access.

Cited pages since the review

6 of 6 cited pages read

No page this bundle cites that has been read changed since 6 Oct 2026.

Downloads

Built from this bundle and the live endpoint data

Entries with {tenantid} are left out of downloads until you fill in your value.

FormatDestinationsLeft outDownload
Plain list, one per line188 Open
GSA V1 domain list1016 Open
GSA V1 Graph request body1115 Download
GSA V2 rules (review JSON)1115 Download
GSA V2 rules (CSV)1115 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/gsa-client. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle gsa-client -Value @{ tenantid = '...' } from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Expected to reach web filtering8expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
DestinationPortsPurposeEvidence
13.107.232.0/24 — Global Secure Access service IP range PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

13.107.233.0/24 — Global Secure Access service IP range PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

150.171.15.0/24 — Global Secure Access service IP rangeThe same 8 ranges appear on the Cisco, Netskope and Palo Alto pages. No port or per-range purpose is given; for IP-only firewalls. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

150.171.18.0/24 — Global Secure Access service IP range PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

150.171.19.0/24 — Global Secure Access service IP range PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

150.171.20.0/24 — Global Secure Access service IP range PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

151.206.0.0/16 — Global Secure Access service IP range PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

www.msftconnecttest.com TCP 80 Windows NCSI active probe; the GSA health check 'Can connect to the internet' depends on NCSIVerbatim in the NCSI page's Proxies section, which the GSA health check links to. Port 80 is inferred from 'An active probe is an http request'. The install page also says the client shows 'could not connect to the Internet' when no internet or captive portal is detected. PublishedNetwork Connectivity Status Indicator overview for Windows
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

Not determined17public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
<tenantid>.auth-backup.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific backup auth edgeTemplate FQDN. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.auth.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific auth (Microsoft Entra channel) edgeTemplate FQDN; purpose inferred from the name. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.internet-backup.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific backup Internet Access edgeTemplate FQDN. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.internet.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific Internet Access edgeTemplate: replace <tenantid> with the tenant GUID. Port 443 from the health checks: Windows 'Edge is reachable' and the macOS example 'nc -vz <guid>.m365.client.globalsecureaccess.microsoft.com 443'. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.m365-backup.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific backup Microsoft traffic edgeTemplate FQDN. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.m365.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific Microsoft traffic (M365) edgeTemplate FQDN. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.private-backup.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific backup Private Access edgeTemplate FQDN; 'backup' role inferred from the name. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

<tenantid>.private.client.globalsecureaccess.microsoft.com TCP 443 Tenant-specific Private Access edgeTemplate FQDN. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

aps.globalsecureaccess.microsoft.com — Global Secure Access service endpoint (purpose not documented)The page says these entries 'need to be present in the app profiles for every scenario'. The function of 'aps' is not explained anywhere I found. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

auth.edgediagnostic.globalsecureaccess.microsoft.com — Edge health diagnostic probe for the auth (Microsoft Entra) channelPurpose inferred from the name. The install page lists the client channels as 'Microsoft Entra, Microsoft 365, Private Access, Internet Access'. Port not stated. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.edgediagnostic.globalsecureaccess.microsoft.com — Client health probing; must bypass any outbound proxy (PAC exclusion)The page says: 'add the FQDN used for health probing to the exclusions list'. The macOS health check page uses the same string. CuratedTroubleshoot the Global Secure Access client for Windows: Health check tabPublished as the PAC dnsDomainIs suffix '.edgediagnostic.globalsecureaccess.microsoft.com' (leading dot, no asterisk); rewritten as a wildcard to fit the kind schema.
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

*.globalsecureaccess.microsoft.com TCP 443 Global Secure Access service edges, health probes and policy (umbrella for all GSA service FQDNs)Same string on the Netskope and Palo Alto coexistence pages. The Advanced diagnostics page describes ForwardingProfile.json as holding 'the Global Secure Access service edge IP address your client connects to (*.globalsecureaccess.microsoft.com)'. Port 443 comes from the Windows health check 'Edge is reachable' (Test-NetConnection -ComputerName <edge's fqdn> -Port 443). The GSA page says not to route it through an outbound proxy and to use a PAC exclusion. PublishedSecurity Service Edge (SSE) coexistence with Microsoft and Cisco Secure Access
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

internet.edgediagnostic.globalsecureaccess.microsoft.com — Edge health diagnostic probe for the Internet Access channelPurpose inferred from the name and the health check's 'Diagnostic URLs in forwarding profile'; the page gives no purpose. Covered by the *.globalsecureaccess wildcard. Port not stated. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

m365.edgediagnostic.globalsecureaccess.microsoft.com — Edge health diagnostic probe for the Microsoft 365/Microsoft traffic channelPurpose inferred from the name. Port not stated. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

private.edgediagnostic.globalsecureaccess.microsoft.com — Edge health diagnostic probe for the Private Access channelPurpose inferred from the name. Port not stated. PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

entra.microsoft.comoptional TCP 443 Admin download of the client (Global Secure Access > Connect > Client download)Admin and packaging step only; devices don't need it at runtime. Linked as https://entra.microsoft.com. PublishedInstall the Global Secure Access client for Windows
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

https://aka.ms/GlobalSecureAccess-WindowsOnArmoptional TCP 443 Download link for the separate Windows on Arm (Arm64) client installerVerbatim in the link href; the page text also shows 'aka.ms/GlobalSecureAccess-WindowsOnArm'. On 2026-10-06 it redirected to https://gsa-installers-prod-ehchedbkcjeqg3hp.b01.azurefd.net/installers/preview/GlobalSecureAccessInstaller_arm64_2.32.294.exe. That target is observed, not published; do not allowlist it. PublishedInstall the Global Secure Access client for Windows
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Probably taken before Internet Access1public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
DestinationPortsPurposeEvidence
login.microsoftonline.com TCP 443 Microsoft Entra authentication of the user/device token used by the clientOther Entra endpoints (device registration, PRT) are probably needed as well but are not documented by GSA. Source them from the Microsoft 365 or Entra endpoint lists. CuratedTroubleshoot the Global Secure Access client for Windows: Health check tab · set 56The health check says the client 'successfully authenticates to Microsoft Entra', but no GSA page names this hostname as a client requirement. It appears on the Cisco/Netskope pages only in the Microsoft 365 traffic-profile bypass list.
Microsoft Entra system profile · indicated, not confirmed

In Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current