Global Secure Access client
What the Global Secure Access client itself needs: its service edges, health probes and the sign-in it relies on. Exclude these from any other proxy.
Managed device · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400 · Global Secure Access
Microsoft publishes these service FQDNs and IP ranges as bypass lists on its SSE coexistence pages; there is no standalone network requirements page. Replace <tenantid> with your tenant ID. The client needs secure DNS (DoH/DoT) disabled, tunnels IPv4 only, and does not tunnel QUIC for Internet Access.
Cited pages since the review
6 of 6 cited pages readNo page this bundle cites that has been read changed since 6 Oct 2026.
Downloads
Built from this bundle and the live endpoint dataEntries with {tenantid} are left out of downloads until you fill in your value.
| Format | Destinations | Left out | Download |
|---|---|---|---|
| Plain list, one per line | 18 | 8 | Open |
| GSA V1 domain list | 10 | 16 | Open |
| GSA V1 Graph request body | 11 | 15 | Download |
| GSA V2 rules (review JSON) | 11 | 15 | Download |
| GSA V2 rules (CSV) | 11 | 15 | Download |
"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.
The same entries are JSON at /api/v1/access-bundles/gsa-client. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle gsa-client -Value @{ tenantid = '...' } from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.
Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.
Expected to reach web filtering8expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
13. |
— | Global Secure Access service IP range | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
13. |
— | Global Secure Access service IP range | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
150. |
— | Global Secure Access service IP rangeThe same 8 ranges appear on the Cisco, Netskope and Palo Alto pages. No port or per-range purpose is given; for IP-only firewalls. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
150. |
— | Global Secure Access service IP range | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
150. |
— | Global Secure Access service IP range | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
150. |
— | Global Secure Access service IP range | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
151. |
— | Global Secure Access service IP range | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
www. |
TCP 80 | Windows NCSI active probe; the GSA health check 'Can connect to the internet' depends on NCSIVerbatim in the NCSI page's Proxies section, which the GSA health check links to. Port 80 is inferred from 'An active probe is an http request'. The install page also says the client shows 'could not connect to the Internet' when no internet or captive portal is detected. | PublishedNetwork Connectivity Status Indicator overview for WindowsInternet Access profile · indicated, not confirmedNot in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published. |
Not determined17public material doesn't settle it; check the client's forwarding profile
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
<tenantid>. |
TCP 443 | Tenant-specific backup auth edgeTemplate FQDN. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific auth (Microsoft Entra channel) edgeTemplate FQDN; purpose inferred from the name. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific backup Internet Access edgeTemplate FQDN. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific Internet Access edgeTemplate: replace <tenantid> with the tenant GUID. Port 443 from the health checks: Windows 'Edge is reachable' and the macOS example 'nc -vz <guid>.m365.client.globalsecureaccess.microsoft.com 443'. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific backup Microsoft traffic edgeTemplate FQDN. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific Microsoft traffic (M365) edgeTemplate FQDN. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific backup Private Access edgeTemplate FQDN; 'backup' role inferred from the name. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
<tenantid>. |
TCP 443 | Tenant-specific Private Access edgeTemplate FQDN. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
aps. |
— | Global Secure Access service endpoint (purpose not documented)The page says these entries 'need to be present in the app profiles for every scenario'. The function of 'aps' is not explained anywhere I found. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
auth. |
— | Edge health diagnostic probe for the auth (Microsoft Entra) channelPurpose inferred from the name. The install page lists the client channels as 'Microsoft Entra, Microsoft 365, Private Access, Internet Access'. Port not stated. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
— | Client health probing; must bypass any outbound proxy (PAC exclusion)The page says: 'add the FQDN used for health probing to the exclusions list'. The macOS health check page uses the same string. | CuratedTroubleshoot the Global Secure Access client for Windows: Health check tabPublished as the PAC dnsDomainIs suffix '.edgediagnostic.globalsecureaccess.microsoft.com' (leading dot, no asterisk); rewritten as a wildcard to fit the kind schema.Microsoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
*. |
TCP 443 | Global Secure Access service edges, health probes and policy (umbrella for all GSA service FQDNs)Same string on the Netskope and Palo Alto coexistence pages. The Advanced diagnostics page describes ForwardingProfile.json as holding 'the Global Secure Access service edge IP address your client connects to (*.globalsecureaccess.microsoft.com)'. Port 443 comes from the Windows health check 'Edge is reachable' (Test-NetConnection -ComputerName <edge's fqdn> -Port 443). The GSA page says not to route it through an outbound proxy and to use a PAC exclusion. | PublishedSecurity Service Edge (SSE) coexistence with Microsoft and Cisco Secure AccessMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
internet. |
— | Edge health diagnostic probe for the Internet Access channelPurpose inferred from the name and the health check's 'Diagnostic URLs in forwarding profile'; the page gives no purpose. Covered by the *.globalsecureaccess wildcard. Port not stated. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
m365. |
— | Edge health diagnostic probe for the Microsoft 365/Microsoft traffic channelPurpose inferred from the name. Port not stated. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
private. |
— | Edge health diagnostic probe for the Private Access channelPurpose inferred from the name. Port not stated. | PublishedLearn about Security Service Edge (SSE) coexistence with Microsoft and ZscalerMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
entra.optional |
TCP 443 | Admin download of the client (Global Secure Access > Connect > Client download)Admin and packaging step only; devices don't need it at runtime. Linked as https://entra.microsoft.com. | PublishedInstall the Global Secure Access client for WindowsMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
https:/optional |
TCP 443 | Download link for the separate Windows on Arm (Arm64) client installerVerbatim in the link href; the page text also shows 'aka.ms/GlobalSecureAccess-WindowsOnArm'. On 2026-10-06 it redirected to https://gsa-installers-prod-ehchedbkcjeqg3hp.b01.azurefd.net/installers/preview/GlobalSecureAccessInstaller_arm64_2.32.294.exe. That target is observed, not published; do not allowlist it. | PublishedInstall the Global Secure Access client for WindowsMicrosoft traffic profile · possible, not confirmedIn Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. |
Probably taken before Internet Access1public material indicates the Microsoft Entra system profile or the Microsoft traffic profile takes them first, so web filtering wouldn't evaluate them; not confirmed
| Destination | Ports | Purpose | Evidence |
|---|---|---|---|
login. |
TCP 443 | Microsoft Entra authentication of the user/device token used by the clientOther Entra endpoints (device registration, PRT) are probably needed as well but are not documented by GSA. Source them from the Microsoft 365 or Entra endpoint lists. | CuratedTroubleshoot the Global Secure Access client for Windows: Health check tab · set 56The health check says the client 'successfully authenticates to Microsoft Entra', but no GSA page names this hostname as a client requirement. It appears on the Cisco/Netskope pages only in the Microsoft 365 traffic-profile bypass list.Microsoft Entra system profile · indicated, not confirmedIn Microsoft 365 endpoint set 56, one of the Entra identity sets. Microsoft documents that the always-on Entra system profile covers sign-in and Graph, and that the Microsoft traffic profile is built from this list, so it is expected to be taken before Internet Access. Microsoft publishes neither profile's host list. |