182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Access bundles

What a locked-down admin workstation or managed device has to reach, one job at a time, with every destination traced to the page that publishes it. Download a bundle as a plain list or in Global Secure Access web filtering formats.

Managed device Defender for Endpoint (streamlined) Streamlined device connectivity for Microsoft Defender for Endpoint on Windows, with the update, certificate validation, SmartScreen and Live Response hosts. 21 destinations 0 expected at web filtering 1 probably taken firstReviewed 6 Oct 2026Managed device Global Secure Access client What the Global Secure Access client itself needs: its service edges, health probes and the sign-in it relies on. Exclude these from any other proxy. 26 destinations 8 expected at web filtering 1 probably taken first2 curatedReviewed 6 Oct 2026Managed device Intune-managed Windows devices The Intune admin center plus what managed Windows devices need: enrollment and check-in, Win32 app and script delivery, push notifications, Autopilot, attestation, the Store API and optional Remote Help. 227 destinations 40 expected at web filtering 89 probably taken firstReviewed 6 Oct 2026Managed device Windows Update and Microsoft Store Windows Update, Delivery Optimization and the Microsoft Store for managed Windows devices, with optional Windows Autopatch hosts. 32 destinations 2 expected at web filtering 1 probably taken firstReviewed 6 Oct 2026Managed device Windows 365 and Azure Virtual Desktop What an end-user device needs to connect to Cloud PCs and Azure Virtual Desktop sessions with Windows App, the Remote Desktop clients or the web client. The Cloud PCs and session hosts have their own, longer list. 95 destinations 4 expected at web filtering 48 probably taken firstReviewed 6 Oct 2026Managed device Certificate revocation and issuers Revocation (CRL and OCSP) and issuer (AIA) hosts for the certificate authorities behind Microsoft's services. Blocked revocation checks make TLS clients either refuse the connection or wait for timeouts before giving up, so sign-ins, updates and agents fail or slow down. 35 destinations 0 expected at web filtering 0 probably taken firstReviewed 6 Oct 2026Managed device Microsoft Edge Microsoft Edge updates, configuration, profile sign-in, sync and SmartScreen on a managed device. 30 destinations 0 expected at web filtering 5 probably taken firstReviewed 6 Oct 2026

Global Secure Access web filtering: V1 and V2

What decides whether a destination gets through
  1. Which profile takes it? GSA checks the always-on Microsoft Entra system profile (sign-in, Graph, certificate validation) and the Microsoft traffic profile (built from the Microsoft 365 endpoint list) before Internet Access. Microsoft documents that traffic the Microsoft traffic profile can acquire is acquired only there, even when a rule is set to Bypass. It publishes neither profile's host list, so bundles show how strongly the public material supports each call, and none of it is confirmed. Your tenant's real rules are in the GSA client: Advanced diagnostics, Forwarding profile.
  2. V2 runs first. A V2 Block is final. A V2 Allow is not: the request then goes to V1.
  3. V1 runs second and can still block what V2 allowed, including from a lower-priority profile. A destination that is allowed in V2 but still blocked usually has a V1 policy in the way.
  4. V2 matching is broader. A V1 domain rule matched the host; the same domain as a V2 URL destination matches the address and its paths.
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current