{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Okta sign-in",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "*.okta.com",
          "purpose": "Okta service domains for commercial orgs",
          "required": true,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of okta.com but not okta.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.mtls.okta.com",
          "purpose": "Okta mutual-TLS endpoints for commercial orgs",
          "required": true,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of mtls.okta.com but not mtls.okta.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.oktacdn.com",
          "purpose": "Okta static sign-in assets served from its CDN",
          "required": true,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__CDN",
          "caveats": [
            "A *. wildcard matches subdomains of oktacdn.com but not oktacdn.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "okta-featureflag-edge.azureedge.net",
          "purpose": "Okta feature-flag edge endpoint listed for the DNS allow list",
          "required": true,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__CDN",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.awsglobalaccelerator.com",
          "purpose": "AWS Global Accelerator front ends used by Okta",
          "required": true,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of awsglobalaccelerator.com but not awsglobalaccelerator.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.oktapreview.com",
          "purpose": "Okta preview (sandbox) orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of oktapreview.com but not oktapreview.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.mtls.oktapreview.com",
          "purpose": "Okta mutual-TLS endpoints for preview orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of mtls.oktapreview.com but not mtls.oktapreview.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.okta-emea.com",
          "purpose": "Okta orgs in the EMEA cell",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of okta-emea.com but not okta-emea.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.mtls.okta-emea.com",
          "purpose": "Okta mutual-TLS endpoints for EMEA orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of mtls.okta-emea.com but not mtls.okta-emea.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.kerberos.okta.com",
          "purpose": "Okta Kerberos endpoints for commercial orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of kerberos.okta.com but not kerberos.okta.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.kerberos.okta-emea.com",
          "purpose": "Okta Kerberos endpoints for EMEA orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of kerberos.okta-emea.com but not kerberos.okta-emea.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.kerberos.oktapreview.com",
          "purpose": "Okta Kerberos endpoints for preview orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of kerberos.oktapreview.com but not kerberos.oktapreview.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.okta-gov.com",
          "purpose": "Okta for Government orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of okta-gov.com but not okta-gov.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.mtls.okta-gov.com",
          "purpose": "Okta mutual-TLS endpoints for Government orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of mtls.okta-gov.com but not mtls.okta-gov.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.okta.mil",
          "purpose": "Okta DoD orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of okta.mil but not okta.mil itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.mtls.okta.mil",
          "purpose": "Okta mutual-TLS endpoints for DoD orgs",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "A *. wildcard matches subdomains of mtls.okta.mil but not mtls.okta.mil itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.digicert.com",
          "purpose": "Certificate revocation (OCSP) for Okta certificates",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl3.digicert.com",
          "purpose": "Certificate revocation (CRL) for Okta certificates",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "crl4.digicert.com",
          "purpose": "Certificate revocation (CRL) for Okta certificates",
          "required": false,
          "source": "https://help.okta.com/oie/en-us/content/topics/security/ip-address-allow-listing.htm#security-ip-address-allow-listing__ImplementationDetails",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}