Summary
- Broadcom's current notice sets September 29 for retiring old Paris localization-zone addresses, following a September 1 relocation date.
- The provider warns of possible Microsoft access failures tied to IP geolocation; gateway connectivity and application trust require separate checks.
September 29 is the next important date in Broadcom's Paris Cloud Secure Web Gateway migration. That is when the current notice schedules retirement of the old addresses. The replacement compute location is Dover in the United Kingdom, while the service being moved is the Paris localization zone.
The change is already under way according to Broadcom's status page. Its August 17 update supersedes the original schedule with a September 1 relocation and September 29 retirement. Those dates describe the published plan, not evidence that every customer has migrated. Broadcom migration notice.
A location label is not a location decision
Localization zones let Cloud SWG request content using addresses intended to match the end user's country. That function is different from the physical location of the compute point of presence. It is also different from the country that another platform assigns to an address.
An August 28 update makes the latter distinction concrete. Broadcom says customers using Microsoft Conditional Access through the relocated point of presence may lose access to Microsoft services because Microsoft incorrectly geolocates the new Cloud SWG addresses. This is Broadcom's explanation of a possible customer problem; the notice does not provide an independently verified affected-user count or outage duration.
Microsoft's documentation explains the dependency. Conditional Access can use a public IP address or Authenticator GPS for location. When location is determined by IP, Microsoft maps that address to a country or region using a periodically updated table. A private address inside an office network is not the public address observed by the service. Microsoft network-condition documentation.
An enterprise can therefore retain working connectivity yet encounter a different application-access decision. The gateway operator controls one part of the path; the identity platform interprets another input, and the customer owns the policy that acts on it.
Automatic redirection has a limited meaning
Broadcom distinguishes connection methods. Certain agents and traffic using its standard proxy hostname are redirected automatically. IPsec and configurations pinned to a specific point of presence or address have separate customer responsibilities. The notice also separates firewall access to the gateway from third-party applications accepting the gateway's outgoing addresses. None is a universal assurance that every sign-in will remain unchanged.
Nor should a migration allowlist be treated automatically as a trusted corporate network. Microsoft warns that adding non-dedicated or non-enumerable outgoing addresses to trusted named-location rules can weaken security. That general warning does not establish whether every address in Broadcom's notice is shared; it explains why the two decisions must not be collapsed. Microsoft continuous-access documentation.
For buyers of managed security, the commercial lesson is a boundary of the service. Provider-managed routing can reduce migration work, but cannot silently settle every customer's identity-policy assumptions. The announcement supplies no measured migration cost, price change or data-residency assurance.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
