{
  "format": "changeintel.gsa-web-filtering-v2",
  "graphShapeDocumented": false,
  "note": "Neutral review format. Create the rule in the Microsoft Entra admin center: Global Secure Access \u003E Secure \u003E Web Filtering Policies (V2).",
  "rules": [
    {
      "name": "ChangeIntel Windows 365 and Azure Virtual Desktop",
      "action": "Allow",
      "destinations": [
        {
          "type": "url",
          "value": "*.wvd.microsoft.com",
          "purpose": "Azure Virtual Desktop service traffic",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of wvd.microsoft.com but not wvd.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.service.windows.cloud.microsoft",
          "purpose": "Service traffic",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of service.windows.cloud.microsoft but not service.windows.cloud.microsoft itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.windows.cloud.microsoft",
          "purpose": "Service traffic",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of windows.cloud.microsoft but not windows.cloud.microsoft itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "windows.cloud.microsoft",
          "purpose": "Connection center (web client and Windows App)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 184 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.windows.static.microsoft",
          "purpose": "Service traffic (static content)",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of windows.static.microsoft but not windows.static.microsoft itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 193 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "windows365.microsoft.com",
          "purpose": "Windows 365 service traffic",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline.com",
          "purpose": "Authentication to Microsoft Online Services",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.microsoft.com",
          "purpose": "Service traffic",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.servicebus.windows.net",
          "purpose": "Troubleshooting data",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of servicebus.windows.net but not servicebus.windows.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did."
          ]
        },
        {
          "type": "url",
          "value": "ecs.office.com",
          "purpose": "Connection center",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 147 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.events.data.microsoft.com",
          "purpose": "Client telemetry",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of events.data.microsoft.com but not events.data.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.cdn.office.net",
          "purpose": "Automatic client updates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of cdn.office.net but not cdn.office.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 47 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "go.microsoft.com",
          "purpose": "Microsoft FWLinks",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "aka.ms",
          "purpose": "Microsoft URL shortener",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Teams / Skype endpoint set 17 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "learn.microsoft.com",
          "purpose": "Documentation links",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "privacy.microsoft.com",
          "purpose": "Privacy statement link",
          "required": false,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.microsoft.com",
          "purpose": "Certificates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftaik.azure.net",
          "purpose": "Certificates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftaik.azure.net but not microsoftaik.azure.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "*.aikcertaia.microsoft.com",
          "purpose": "Certificates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "A *. wildcard matches subdomains of aikcertaia.microsoft.com but not aikcertaia.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "azcsprodeusaikpublish.blob.core.windows.net",
          "purpose": "Certificates",
          "required": true,
          "source": "https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure#end-user-devices",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "HTTP only: published for port 80."
          ]
        },
        {
          "type": "url",
          "value": "*.auth.microsoft.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of auth.microsoft.com but not auth.microsoft.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftidentity.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msftidentity.com but not msftidentity.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msidentity.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msidentity.com but not msidentity.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "account.activedirectory.windowsazure.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "accounts.accesscontrol.windows.net",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "adminwebservice.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "api.passwordreset.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "autologon.microsoftazuread-sso.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "becws.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ccs.login.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "clientconfig.microsoftonline-p.net",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "companymanager.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "device.login.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "graph.windows.net",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login-us.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoft.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.microsoftonline-p.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "login.windows.net",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "logincert.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "loginex.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "nexus.microsoftonline-p.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "passwordreset.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "provisioningapi.microsoftonline.com",
          "purpose": "Common endpoint set 56 (Allow)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.hip.live.com",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of hip.live.com but not hip.live.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftonline-p.com",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftonline-p.com but not microsoftonline-p.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.microsoftonline.com",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of microsoftonline.com but not microsoftonline.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msauth.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msauth.net but not msauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msauthimages.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msauthimages.net but not msauthimages.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msecnd.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msecnd.net but not msecnd.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftauth.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msftauth.net but not msftauth.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.msftauthimages.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of msftauthimages.net but not msftauthimages.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.phonefactor.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of phonefactor.net but not phonefactor.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "enterpriseregistration.windows.net",
          "purpose": "Common endpoint set 59 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "Public material indicates the Microsoft Entra system profile takes this before Internet Access (indicated, not confirmed), so this rule is probably redundant. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.entrust.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of entrust.net but not entrust.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.geotrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of geotrust.com but not geotrust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.omniroot.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of omniroot.com but not omniroot.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.public-trust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of public-trust.com but not public-trust.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.symcb.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of symcb.com but not symcb.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.symcd.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of symcd.com but not symcd.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.verisign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of verisign.com but not verisign.com itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "*.verisign.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "A *. wildcard matches subdomains of verisign.net but not verisign.net itself; list the apex separately only if a source publishes it.",
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cacerts.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "cert.int-x3.letsencrypt.org",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.globalsign.net",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl.identrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl3.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "crl4.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "isrg.trustid.ocsp.identrust.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "mscrl.microsoft.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp.msocsp.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocsp2.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "ocspx.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "oneocsp.microsoft.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 50 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "secure.globalsign.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        },
        {
          "type": "url",
          "value": "www.digicert.com",
          "purpose": "Common endpoint set 125 (Default)",
          "required": true,
          "source": "https://endpoints.office.com/endpoints/Worldwide",
          "caveats": [
            "V2 matching broadens: this FQDN becomes a URL destination that matches the address and its sub-paths, not only the exact host as a V1 FQDN rule did.",
            "In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile."
          ]
        }
      ]
    }
  ],
  "notes": [
    "In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation).",
    "V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths.",
    "A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic.",
    "V2 runs before V1. A V2 Block is terminal; a V2 Allow isn\u0027t, so a V1 policy can still block the same traffic.",
    "Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL."
  ]
}