Access bundles
What a locked-down admin workstation or managed device has to reach, one job at a time, with every destination traced to the page that publishes it. Download a bundle as a plain list or in Global Secure Access web filtering formats.
Managed device
Defender for Endpoint (streamlined)
Streamlined device connectivity for Microsoft Defender for Endpoint on Windows, with the update, certificate validation, SmartScreen and Live Response hosts.
21 destinations
0 expected at web filtering
1 probably taken firstReviewed 6 Oct 2026Managed device
Global Secure Access client
What the Global Secure Access client itself needs: its service edges, health probes and the sign-in it relies on. Exclude these from any other proxy.
26 destinations
8 expected at web filtering
1 probably taken first2 curatedReviewed 6 Oct 2026Managed device
Intune-managed Windows devices
The Intune admin center plus what managed Windows devices need: enrollment and check-in, Win32 app and script delivery, push notifications, Autopilot, attestation, the Store API and optional Remote Help.
227 destinations
40 expected at web filtering
89 probably taken firstReviewed 6 Oct 2026Managed device
Windows Update and Microsoft Store
Windows Update, Delivery Optimization and the Microsoft Store for managed Windows devices, with optional Windows Autopatch hosts.
32 destinations
2 expected at web filtering
1 probably taken firstReviewed 6 Oct 2026Managed device
Windows 365 and Azure Virtual Desktop
What an end-user device needs to connect to Cloud PCs and Azure Virtual Desktop sessions with Windows App, the Remote Desktop clients or the web client. The Cloud PCs and session hosts have their own, longer list.
95 destinations
4 expected at web filtering
48 probably taken firstReviewed 6 Oct 2026Managed device
Certificate revocation and issuers
Revocation (CRL and OCSP) and issuer (AIA) hosts for the certificate authorities behind Microsoft's services. Blocked revocation checks make TLS clients either refuse the connection or wait for timeouts before giving up, so sign-ins, updates and agents fail or slow down.
35 destinations
0 expected at web filtering
0 probably taken firstReviewed 6 Oct 2026Managed device
Microsoft Edge
Microsoft Edge updates, configuration, profile sign-in, sync and SmartScreen on a managed device.
30 destinations
0 expected at web filtering
5 probably taken firstReviewed 6 Oct 2026
Global Secure Access web filtering: V1 and V2
What decides whether a destination gets through- Which profile takes it? GSA checks the always-on Microsoft Entra system profile (sign-in, Graph, certificate validation) and the Microsoft traffic profile (built from the Microsoft 365 endpoint list) before Internet Access. Microsoft documents that traffic the Microsoft traffic profile can acquire is acquired only there, even when a rule is set to Bypass. It publishes neither profile's host list, so bundles show how strongly the public material supports each call, and none of it is confirmed. Your tenant's real rules are in the GSA client: Advanced diagnostics, Forwarding profile.
- V2 runs first. A V2 Block is final. A V2 Allow is not: the request then goes to V1.
- V1 runs second and can still block what V2 allowed, including from a lower-priority profile. A destination that is allowed in V2 but still blocked usually has a V1 policy in the way.
- V2 matching is broader. A V1 domain rule matched the host; the same domain as a V2 URL destination matches the address and its paths.
- V1 FQDN destinations take the domain name only, without protocol, port or path. Use *.domain.com for subdomains; it doesn't match domain.com itself, so list both. Separate several FQDNs with commas and no spaces. How to configure Global Secure Access web content filtering
- In V1 the action is defined on the policy and rules carry destinations only; a V1 policy has no default action and acts only when a rule matches. Web filtering in Global Secure Access (V2)
- In V2 a security profile contains exactly one web filtering policy. Each rule carries its own Allow or Block action and the policy has a default action (Allow, Block, or the preview Continue Evaluation). Web filtering in Global Secure Access (V2)
- V2 has no standalone FQDN type: FQDNs are expressed as URL destinations, and a URL destination matches the address and its sub-paths. Web filtering in Global Secure Access (V2)
- A former exact-host FQDN evaluated with URL logic can match sub-paths of the address rather than only the exact host; review destinations to confirm they match the intended traffic. Web filtering in Global Secure Access (V2)
- V2 runs before V1. A V2 Block is terminal; a V2 Allow isn't, so a V1 policy can still block the same traffic. Web filtering in Global Secure Access (V2)
- Once any V2 web filtering policy exists, V1 policies can only be edited or deleted, not created. Migrate web content filtering policies from V1 to V2
- Up to 256 security profiles, 1,000 policies, 1,000 rules and 8,000 destinations (IP, FQDN, URL or web category) per tenant. The platform assumes ports 80 and 443. Known limitations for Global Secure Access: Internet Access limitations
- The URL filtering preview supports a maximum of 1,000 URLs per tenant. How to configure Global Secure Access web content filtering
- Without TLS inspection, HTTPS traffic is evaluated by Server Name Indication (SNI); only unencrypted HTTP exposes the full URL. How to configure Global Secure Access web content filtering
- The Microsoft traffic profile derives its rules from the Microsoft 365 IP and FQDN list, and traffic available in it can only be acquired there, not by the Internet Access profile. Learn about the Microsoft traffic profile
- Microsoft Graph (beta) creates a V1 policy with POST /networkaccess/filteringPolicies: fqdnFilteringRule rules hold fqdn destinations and the policy carries the action. Configure Microsoft Entra Internet Access using Microsoft Graph APIs