{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Intune-managed Windows devices",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "intune.microsoft.com",
          "purpose": "Microsoft Intune admin center",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/account-sign-up#intune-admin-portal-url",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.manage.microsoft.com",
          "purpose": "Intune client and host service: enrollment, check-in, policy, IME/Win32 content (AFD)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "A *. wildcard matches subdomains of manage.microsoft.com but not manage.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "manage.microsoft.com",
          "purpose": "Intune client and host service (apex)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.dm.microsoft.com",
          "purpose": "Intune / Defender for Endpoint security settings management / Endpoint Privilege Management enrollment, check-in and reporting",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "A *. wildcard matches subdomains of dm.microsoft.com but not dm.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "EnterpriseEnrollment.manage.microsoft.com",
          "purpose": "Windows MDM enrollment discovery",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.microsoft.com",
          "purpose": "Microsoft Graph (Intune requires unauthenticated proxy access for some tasks; admin center data plane)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#access-for-managed-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.azureedge.net",
          "purpose": "Legacy Azure CDN (Intune says some tasks require unauthenticated proxy access)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#access-for-managed-devices",
          "caveats": [
            "A *. wildcard matches subdomains of azureedge.net but not azureedge.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Broader than the Microsoft 365 entries it includes (such as set 27): those parts are expected to go to a Microsoft profile and the rest to Internet Access. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "go.microsoft.com",
          "purpose": "Endpoint discovery",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "config.edge.skype.com",
          "purpose": "Feature deployment / flighting dependency",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ecs.office.com",
          "purpose": "Feature deployment dependency",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "fd.api.orgmsg.microsoft.com",
          "purpose": "Organizational messages",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ris.prod.api.personalization.ideas.microsoft.com",
          "purpose": "Organizational messages",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "account.live.com",
          "purpose": "Microsoft account / device authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.live.com",
          "purpose": "Microsoft account / device authentication; Windows Autopilot deployment service",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 97 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swda01-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swda02-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdb01-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdb02-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdc01-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdd01-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdd02-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdin01-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdin02-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "swdc02-mscdn.manage.microsoft.com",
          "purpose": "Win32 app content CDN (MEM - Win32Apps)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/scripts/powershell-add-internet-access-device-compliance-bypasses#sample-script",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aam-content-cdn.manage.microsoft.com",
          "purpose": "Enterprise App Catalog app content",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#intune-core-service",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswda-afd-primary.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (North America tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswda-afd-secondary.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (North America tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswda-afd-hotfix.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (North America tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswdb-afd-primary.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (Europe tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswdb-afd-secondary.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (Europe tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswdb-afd-hotfix.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (Europe tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswdc-afd-primary.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (Asia Pacific tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswdc-afd-secondary.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (Asia Pacific tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "imeswdc-afd-hotfix.manage.microsoft.com",
          "purpose": "Intune Management Extension CDN (Asia Pacific tenants): Win32 apps, PowerShell scripts, remediations, custom compliance",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "go-amer.trouter.communications.svc.cloud.microsoft",
          "purpose": "Listed with IME CDN and Remote Help endpoints (NA / rest of world tenants)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "go-eu.trouter.communications.svc.cloud.microsoft",
          "purpose": "Listed with IME CDN and Remote Help endpoints (EU tenants)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "go-apac.trouter.communications.svc.cloud.microsoft",
          "purpose": "Listed with IME CDN and Remote Help endpoints (APAC tenants)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.events.data.microsoft.com",
          "purpose": "IME client health diagnostics; Endpoint analytics; EPM reporting",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#network-requirements-for-powershell-scripts-and-win32-apps",
          "caveats": [
            "A *. wildcard matches subdomains of events.data.microsoft.com but not events.data.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Microsoft Entra authentication",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#authentication-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.windows.net",
          "purpose": "Azure AD Graph (Entra) dependency",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#authentication-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "enterpriseregistration.windows.net",
          "purpose": "Entra device registration",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#authentication-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "certauth.enterpriseregistration.windows.net",
          "purpose": "Entra device registration (certificate auth)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#authentication-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "config.office.com",
          "purpose": "Office Customization Service (M365 Apps policy)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#authentication-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.officeconfig.msocdn.com",
          "purpose": "Office Customization Service",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#authentication-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of officeconfig.msocdn.com but not officeconfig.msocdn.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 78 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.notify.windows.com",
          "purpose": "Windows Push Notification Services (device actions, immediate sync)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-push-notification-services-wns-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of notify.windows.com but not notify.windows.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 171 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.wns.windows.com",
          "purpose": "Windows Push Notification Services client channel",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-push-notification-services-wns-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of wns.windows.com but not wns.windows.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 SharePoint endpoint set 35 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.do.dsp.mp.microsoft.com",
          "purpose": "Delivery Optimization cloud service",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#delivery-optimization-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of do.dsp.mp.microsoft.com but not do.dsp.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.dl.delivery.mp.microsoft.com",
          "purpose": "Delivery Optimization metadata / Windows and Store content",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#delivery-optimization-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of dl.delivery.mp.microsoft.com but not dl.delivery.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.windowsupdate.com",
          "purpose": "Windows Update (Autopilot dependency)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of windowsupdate.com but not windowsupdate.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 164 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.prod.do.dsp.mp.microsoft.com",
          "purpose": "Delivery Optimization service (Autopilot dependency)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of prod.do.dsp.mp.microsoft.com but not prod.do.dsp.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.delivery.mp.microsoft.com",
          "purpose": "Windows Update / Store delivery (Autopilot dependency)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of delivery.mp.microsoft.com but not delivery.mp.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.update.microsoft.com",
          "purpose": "Windows Update service (Autopilot dependency)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of update.microsoft.com but not update.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "tsfe.trafficshaping.dsp.mp.microsoft.com",
          "purpose": "Windows Update traffic shaping / content regulation",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "adl.windows.com",
          "purpose": "Windows compatibility database updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 19 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "dl.delivery.mp.microsoft.com",
          "purpose": "Windows Update / Delivery Optimization content (apex host)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#consolidated-endpoint-list",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "time.windows.com",
          "purpose": "NTP time sync (Autopilot)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Web filtering assumes ports 80 and 443; port 123 traffic needs a firewall rule instead.",
            "UDP isn\u0027t supported by Internet Access; only the TCP part is filtered.",
            "In Microsoft 365 Intune (MEM) endpoint set 165 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "clientconfig.passport.net",
          "purpose": "Autopilot WNS dependency",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 169 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "windowsphone.com",
          "purpose": "Autopilot WNS dependency",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 169 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.s-microsoft.com",
          "purpose": "Autopilot WNS dependency",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "A *. wildcard matches subdomains of s-microsoft.com but not s-microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 169 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ekop.intel.com",
          "purpose": "Intel firmware TPM EK certificate retrieval (Autopilot self-deploying / pre-provisioning)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 173 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ekcert.spserv.microsoft.com",
          "purpose": "Qualcomm firmware TPM EK certificate retrieval",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ftpm.amd.com",
          "purpose": "AMD firmware TPM EK certificate retrieval",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 173 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftaik.azure.net",
          "purpose": "TPM attestation (Autopilot self-deploying mode and pre-provisioning)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/autopilot/requirements?tabs=networking#service-requirements",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftaik.azure.net but not microsoftaik.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ztd.dds.microsoft.com",
          "purpose": "Windows Autopilot Deployment Service",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/autopilot/requirements?tabs=networking#service-requirements",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftconnecttest.com",
          "purpose": "Network Connection Status Indicator (Autopilot requires internet detection)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/autopilot/requirements?tabs=networking#service-requirements",
          "caveats": [
            "A *. wildcard matches subdomains of msftconnecttest.com but not msftconnecttest.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "lgmsapeweu.blob.core.windows.net",
          "purpose": "Autopilot automatic diagnostics upload (legacy host)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/autopilot/requirements?tabs=networking#service-requirements",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 182 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "amsua0101lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0102lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0201lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0202lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0401lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0402lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0501lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0502lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0601lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0602lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0701lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0702lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0801lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0901lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsua0902lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0101lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0102lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0201lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0202lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0301lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0302lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0501lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0502lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0601lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0701lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0801lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsub0901lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsuc0101lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsuc0201lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsuc0301lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsuc0501lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsuc0601lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsud0101lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "amsuin01lmsas.blob.core.windows.net",
          "purpose": "Autopilot / collect-diagnostics upload storage (region-specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#windows-autopilot-dependencies",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape1.eus.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape2.eus2.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape3.cus.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape4.wus.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape5.scus.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape7.neu.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape8.neu.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape9.neu.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape10.weu.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape11.weu.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape12.weu.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape13.jpe.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape17.jpe.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape18.jpe.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape19.jpe.attest.azure.net",
          "purpose": "Microsoft Azure Attestation for Windows 11 compliance Device Health settings (tenant-region specific)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 186 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "intunemaape6.ncus.attest.azure.net",
          "purpose": "Microsoft Azure Attestation (North America)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#migrating-device-health-attestation-compliance-policies-to-microsoft-azure-attestation",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "displaycatalog.mp.microsoft.com",
          "purpose": "Microsoft Store API (AppInstallManager) catalog",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#microsoft-store",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "purchase.md.mp.microsoft.com",
          "purpose": "Microsoft Store API purchase/acquisition",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#microsoft-store",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "licensing.mp.microsoft.com",
          "purpose": "Microsoft Store API licensing",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#microsoft-store",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "storeedgefd.dsx.mp.microsoft.com",
          "purpose": "Microsoft Store API front door",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#microsoft-store",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cdn.storeedgefd.dsx.mp.microsoft.com",
          "purpose": "Microsoft-hosted Win32 Store app fallback cache",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#microsoft-store",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.support.services.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of support.services.microsoft.com but not support.services.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "teams.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft traffic profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "remoteassistanceprodacs.communication.azure.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 181 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "edge.skype.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aadcdn.msftauth.net",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aadcdn.msauth.net",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "alcdn.msauth.net",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "wcpstatic.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.aria.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of aria.microsoft.com but not aria.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.monitor.azure.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of monitor.azure.com but not monitor.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 181 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "edge.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.trouter.communication.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of trouter.communication.microsoft.com but not trouter.communication.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.trouter.teams.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of trouter.teams.microsoft.com but not trouter.teams.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft traffic profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.trouter.communications.svc.cloud.microsoft",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of trouter.communications.svc.cloud.microsoft but not trouter.communications.svc.cloud.microsoft itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "api.flightproxy.skype.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ecs.communication.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "remotehelp.microsoft.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "remoteassistanceprodacseu.communication.azure.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 181 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.trouter.skype.com",
          "purpose": "Remote Help (optional feature)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/scripts/powershell-add-internet-access-device-compliance-bypasses#sample-script",
          "caveats": [
            "A *. wildcard matches subdomains of trouter.skype.com but not trouter.skype.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 127 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.webpubsub.azure.com",
          "purpose": "Remote Help web pubsub",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#remote-help",
          "caveats": [
            "A *. wildcard matches subdomains of webpubsub.azure.com but not webpubsub.azure.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Intune (MEM) endpoint set 187 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.powershellgallery.com",
          "purpose": "Listed in Intune consolidated FQDN list (purpose not stated)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#consolidated-endpoint-list",
          "caveats": [
            "A *. wildcard matches subdomains of powershellgallery.com but not powershellgallery.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "cdn.oneget.org",
          "purpose": "Listed in Intune consolidated FQDN list (purpose not stated)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#consolidated-endpoint-list",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "aka.ms",
          "purpose": "Listed in Intune consolidated FQDN list (purpose not stated)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/intune/fundamentals/endpoints#consolidated-endpoint-list",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.emdl.ws.microsoft.com",
          "purpose": "Windows Update / Delivery Optimization download (GSA bypass list)",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/entra/global-secure-access/scripts/powershell-add-internet-access-device-compliance-bypasses#sample-script",
          "caveats": [
            "A *. wildcard matches subdomains of emdl.ws.microsoft.com but not emdl.ws.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "emdl.ws.microsoft.com",
          "purpose": "Windows Update download endpoint",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/troubleshoot/windows-client/installing-updates-features-roles/windows-update-issues-troubleshooting#device-cant-access-update-files",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}