{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel PowerShell modules and admin sign-in",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "cdn.powershellgallery.com",
          "purpose": "PowerShell Gallery package discovery and download",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/powershell/gallery/getting-started#network-access-to-the-powershell-gallery",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "cdn.oneget.org",
          "purpose": "PackageManagement (OneGet) CDN, including the NuGet provider bootstrap",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/powershell/gallery/getting-started#network-access-to-the-powershell-gallery",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "*.powershellgallery.com",
          "purpose": "PowerShell Gallery website and the registered PSGallery repository host",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/powershell/gallery/getting-started#network-access-to-the-powershell-gallery",
          "caveats": [
            "A *. wildcard matches subdomains of powershellgallery.com but not powershellgallery.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "go.microsoft.com",
          "purpose": "Redirection service used by the PowerShell Gallery",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/powershell/gallery/getting-started#network-access-to-the-powershell-gallery",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aka.ms",
          "purpose": "Short-link redirection service used by the PowerShell Gallery website",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/powershell/gallery/getting-started#network-access-to-the-powershell-gallery",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Microsoft Entra sign-in for Connect-MgGraph, Connect-Entra and Connect-ExchangeOnline",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.microsoft.com",
          "purpose": "Microsoft Graph API called by Microsoft Graph PowerShell and Microsoft Entra PowerShell",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "outlook.office365.com",
          "purpose": "Exchange Online PowerShell connection endpoint",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#exchange-online",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft traffic profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftauth.net",
          "purpose": "Identity supporting services and CDNs for interactive sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msftauth.net but not msftauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msauth.net",
          "purpose": "Identity supporting services and CDNs for interactive sign-in",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges#microsoft-365-common-and-office-online",
          "caveats": [
            "A *. wildcard matches subdomains of msauth.net but not msauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "https://www.powershellgallery.com/api/v2",
          "purpose": "Default PSGallery repository endpoint used by PowerShellGet and PSResourceGet",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.psresourceget/get-psresourcerepository#example-1",
          "caveats": []
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}