182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Access bundles

What a locked-down admin workstation or managed device has to reach, one job at a time, with every destination traced to the page that publishes it. Download a bundle as a plain list or in Global Secure Access web filtering formats.

Admin workstation Microsoft Entra sign-in and admin Sign in to Microsoft Entra ID, use the Entra admin center and Microsoft Graph, and register security info for MFA. 107 destinations 20 expected at web filtering 48 probably taken first7 curatedReviewed 6 Oct 2026Admin workstation Microsoft 365 admin portals Reach the Microsoft 365, Exchange, SharePoint, Teams, Defender, Purview and Intune admin centers. Use with the Entra sign-in bundle. 29 destinations 0 expected at web filtering 10 probably taken first1 curatedReviewed 6 Oct 2026Admin workstation Azure portal The Azure portal safelist for the public cloud: authentication, the portal framework, account data, and optional per-service hosts. 109 destinations 81 expected at web filtering 15 probably taken first24 curatedReviewed 6 Oct 2026Admin workstation PowerShell modules and admin sign-in Install and update modules from the PowerShell Gallery, then sign in with Microsoft Graph PowerShell, Microsoft Entra PowerShell or Exchange Online PowerShell. 11 destinations 4 expected at web filtering 4 probably taken firstReviewed 6 Oct 2026Admin workstation Okta sign-in Reach your Okta org for sign-in, the dashboard and Okta Verify, with the Okta CDN and the region-specific Okta domains. 20 destinations 17 expected at web filtering 0 probably taken first1 curatedReviewed 6 Oct 2026Admin workstation CyberArk Identity and Privilege Cloud Reach the CyberArk Identity sign-in and the Privilege Cloud portal from an admin workstation, with the certificate checks they rely on. 15 destinations 11 expected at web filtering 0 probably taken first1 curatedReviewed 6 Oct 2026

Global Secure Access web filtering: V1 and V2

What decides whether a destination gets through
  1. Which profile takes it? GSA checks the always-on Microsoft Entra system profile (sign-in, Graph, certificate validation) and the Microsoft traffic profile (built from the Microsoft 365 endpoint list) before Internet Access. Microsoft documents that traffic the Microsoft traffic profile can acquire is acquired only there, even when a rule is set to Bypass. It publishes neither profile's host list, so bundles show how strongly the public material supports each call, and none of it is confirmed. Your tenant's real rules are in the GSA client: Advanced diagnostics, Forwarding profile.
  2. V2 runs first. A V2 Block is final. A V2 Allow is not: the request then goes to V1.
  3. V1 runs second and can still block what V2 allowed, including from a lower-priority profile. A destination that is allowed in V2 but still blocked usually has a V1 policy in the way.
  4. V2 matching is broader. A V1 domain rule matched the host; the same domain as a V2 URL destination matches the address and its paths.
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current