{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Global Secure Access client",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "*.globalsecureaccess.microsoft.com",
          "purpose": "Global Secure Access service edges, health probes and policy (umbrella for all GSA service FQDNs)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-cisco-secure-access-coexistence#bypass-global-secure-access-ips-and-fqdns-in-cisco-secure-accessumbrella",
          "caveats": [
            "A *. wildcard matches subdomains of globalsecureaccess.microsoft.com but not globalsecureaccess.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "internet.edgediagnostic.globalsecureaccess.microsoft.com",
          "purpose": "Edge health diagnostic probe for the Internet Access channel",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-zscaler-coexistence#global-secure-access-service-fqdns-and-ips-bypasses",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "m365.edgediagnostic.globalsecureaccess.microsoft.com",
          "purpose": "Edge health diagnostic probe for the Microsoft 365/Microsoft traffic channel",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-zscaler-coexistence#global-secure-access-service-fqdns-and-ips-bypasses",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "private.edgediagnostic.globalsecureaccess.microsoft.com",
          "purpose": "Edge health diagnostic probe for the Private Access channel",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-zscaler-coexistence#global-secure-access-service-fqdns-and-ips-bypasses",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "auth.edgediagnostic.globalsecureaccess.microsoft.com",
          "purpose": "Edge health diagnostic probe for the auth (Microsoft Entra) channel",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-zscaler-coexistence#global-secure-access-service-fqdns-and-ips-bypasses",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aps.globalsecureaccess.microsoft.com",
          "purpose": "Global Secure Access service endpoint (purpose not documented)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-zscaler-coexistence#global-secure-access-service-fqdns-and-ips-bypasses",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.edgediagnostic.globalsecureaccess.microsoft.com",
          "purpose": "Client health probing; must bypass any outbound proxy (PAC exclusion)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/troubleshoot-global-secure-access-client-diagnostics-health-check#change-the-pac-file",
          "caveats": [
            "A *. wildcard matches subdomains of edgediagnostic.globalsecureaccess.microsoft.com but not edgediagnostic.globalsecureaccess.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Microsoft Entra authentication of the user/device token used by the client",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/troubleshoot-global-secure-access-client-diagnostics-health-check#cached-token",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.msftconnecttest.com",
          "purpose": "Windows NCSI active probe; the GSA health check \u0027Can connect to the internet\u0027 depends on NCSI",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-overview#proxies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "entra.microsoft.com",
          "purpose": "Admin download of the client (Global Secure Access \u003E Connect \u003E Client download)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-install-windows-client#download-the-client",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "https://aka.ms/GlobalSecureAccess-WindowsOnArm",
          "purpose": "Download link for the separate Windows on Arm (Arm64) client installer",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-install-windows-client#prerequisites",
          "caveats": [
            "In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}