Microsoft Global Secure Access Overview

Microsoft Global Secure Access is Microsoft’s Security Service Edge solution for organizations that want to secure access to Microsoft 365, SaaS apps, public internet destinations, and private corporate resources using identity-first Zero Trust controls. Instead of depending only on legacy VPNs or network perimeter rules, Global Secure Access brings network, identity, device, and Conditional Access signals together inside Microsoft Entra.

This guide explains what Microsoft Global Secure Access is, how licensing works, how to download and install the Global Secure Access client, and how to configure Microsoft traffic, Internet Access, and Private Access profiles.

Quick answer

Microsoft Global Secure Access is the unified Microsoft Entra location for Microsoft Entra Internet Access and Microsoft Entra Private Access. Internet Access safeguards public internet traffic, SaaS, and Microsoft 365. Private Access provides Zero Trust access to internal apps and private resources without exposing the entire network through a VPN.


What is Microsoft Global Secure Access?

Microsoft Global Secure Access, often called GSA, is Microsoft’s identity-aware cloud-delivered network security solution. Microsoft positions Global Secure Access as the unifying term for Microsoft Entra Internet Access and Microsoft Entra Private Access. Together, these capabilities form Microsoft’s Security Service Edge approach for securing access from anywhere.

Traditional network security normally starts with the network location. Global Secure Access starts with identity, device state, app context, risk signals, and Conditional Access. This makes it more aligned with Zero Trust principles: verify explicitly, use least privilege access, and assume breach.

For Microsoft 365 administrators, the biggest value is that Global Secure Access can help protect Exchange Online, SharePoint Online, Teams, OneDrive, SaaS applications, internet traffic, and private applications using policies that are closely integrated with Microsoft Entra ID..


Why Global Secure Access matters for Microsoft 365 and Azure environments

  • It helps modernize secure remote access without relying only on legacy VPN designs.
  • It provides identity-aware access controls by using Microsoft Entra ID and Conditional Access.
  • It improves protection for Microsoft 365 services by routing supported Microsoft traffic through the Microsoft traffic profile.
  • It supports private application access through app segments, Quick Access, and private network connectors.
  • It gives administrators better visibility through audit logs, traffic logs, dashboards, and sign-in signals.
  • It supports phased adoption, so organizations can start with pilot groups before expanding to production.

Global Secure Access components explained

Before configuring Global Secure Access, it is important to understand the main components. Many admins confuse Global Secure Access, Entra Internet Access, Entra Private Access, and the Microsoft traffic profile. The table below separates each component clearly.

Component

Purpose

Typical Use Case

Microsoft traffic profile

Routes supported Microsoft 365 traffic through Global Secure Access.

Protect Exchange Online, SharePoint Online, Teams, OneDrive, and Microsoft 365 access.

Microsoft Entra Internet Access

Identity-aware Secure Web Gateway for SaaS and public internet traffic.

Secure internet browsing, control web categories, inspect risky destinations, and manage SaaS access.

Microsoft Entra Private Access

Zero Trust Network Access for internal resources and private applications.

Replace broad VPN access for RDP, line-of-business apps, internal web apps, and private IP/FQDN resources.

Global Secure Access client

Endpoint client that forwards configured traffic profiles to Global Secure Access.

Windows/macOS/mobile device traffic forwarding based on assigned profiles.

Private network connector

Connector used to reach internal resources for Private Access.

Enable access to private apps without exposing the entire network.

Conditional Access integration

Uses network and identity signals to control access.

Require compliant network, block access outside GSA, or apply risk-based access controls.

Microsoft Entra Internet Access

Microsoft Entra Internet Access protects access to internet and SaaS applications using an identity-based Secure Web Gateway approach. It can enforce web filtering, Conditional Access, traffic logging, and context-aware access decisions based on user, device, location, risk, and compliance signals.

Microsoft Entra Private Access

Microsoft Entra Private Access provides secure access to private corporate resources. It is designed to reduce dependency on traditional VPNs by granting access to specific private applications, IP addresses, FQDNs, ports, and protocols instead of placing a user device broadly on the corporate network.

Microsoft traffic profile

The Microsoft traffic profile is especially useful for Microsoft 365 environments. It can route supported Microsoft 365 traffic through Global Secure Access and enable options such as compliant network checks, source IP restoration, Universal Tenant Restrictions, and enhanced visibility for Microsoft 365 access scenarios.


Microsoft Global Secure Access licensing and pricing overview

Licensing is one of the most important sections for this topic because many admins search for Microsoft Global Secure Access pricing, Global Secure Access licensing, or whether Microsoft Entra ID P1 or P2 comes with Global Secure Access. The short answer is that the type of traffic profile and capability you want to use will decide your licensing.

Capability

Common License Requirement

Notes

Microsoft traffic profile

Microsoft Entra ID P1 or P2

Useful for Microsoft 365 traffic and compliant network scenarios.

Microsoft Entra Internet Access

Microsoft Entra Internet Access standalone or Microsoft Entra Suite

Required for full internet and SaaS protection capabilities.

Microsoft Entra Private Access

Microsoft Entra Private Access standalone or Microsoft Entra Suite

Required for private app access, Quick Access, and ZTNA scenarios.

Global Secure Access client

Depends on assigned profile and licensed capability

The client is used to acquire and forward traffic from supported devices.

Remote network connectivity

Requires eligible licensing and tenant prerequisites

Useful for branch office traffic forwarding without installing a client on every endpoint.

Licensing note for production

Always validate licensing in the Microsoft 365 admin center or Microsoft Entra licensing page before enabling production policies. Microsoft may update packaging, standalone availability, and included features over time.

Understand Licensing

To understand the complete features, benefits, and licensing capabilities of Microsoft Entra ID Premium P1, Premium P2, and Entra ID Suites, we have created a dedicated guide. You can check out the detailed article below.


How Microsoft Global Secure Access works

At a high level, Global Secure Access forwards selected traffic from the user device or remote network to Microsoft’s cloud-delivered security service. The service evaluates the traffic based on the enabled traffic profile and applies the relevant access controls, security policies, and Conditional Access signals.

Traffic flow example:

  • User signs in from a supported device.
  • The Global Secure Access client starts and receives the traffic profile assignment.
  • Traffic matching Microsoft, Internet Access, or Private Access profiles is forwarded to Global Secure Access.
  • Microsoft Entra evaluates identity, device, network, and Conditional Access signals.
  • Traffic is allowed, blocked, bypassed, or routed to the required Microsoft 365, SaaS, internet, or private resource.
  • Admins review activity through traffic logs, audit logs, sign-in logs, and dashboards.

Architecture overview

Use this simplified architecture when explaining the solution in customer documentation or internal design reviews:

1. User device or branch network

2. Global Secure Access client or remote network assignment

3. Traffic forwarding profile: Microsoft, Internet Access, or Private Access

4. Microsoft Entra Conditional Access and security evaluation

5. Destination: Microsoft 365, SaaS, internet, or private app


Prerequisites before configuration

Before enabling Global Secure Access in a production tenant, confirm the following prerequisites:

  • A Microsoft Entra tenant with the required licensing for the profile you plan to configure.
    – Microsoft Entra ID P1 or P2 for Microsoft Traffic
    – Microsoft Entra Internet and Private Access required Microsoft Entra Suite
    – Microsoft Defender for Cloud Apps (for deeper integration)
  • Administrative roles such as Global Secure Access Administrator, Conditional Access Administrator, Application Administrator, or Global Administrator based on the task.
  • A pilot user group for testing.
  • At least one break-glass account excluded from blocking policies.
  • Supported devices for the Global Secure Access client.
  • Local administrator permissions or Intune deployment for client installation.
  • A test plan for Microsoft 365 access, private app access, and expected blocked behavior.

    Step-by-Step Configuration of Global Secure Access for Microsoft Traffic and Internet access Profiles

    Start with a pilot group and use report-only mode where possible before enforcing blocking policies.

    Step 1: Enable Microsoft traffic and Internet Access profiles

    • Go to the Microsoft Entra admin center.
    • Navigate to Global Secure Access.
    • Open Connect > Traffic forwarding.
    • Enable the Microsoft traffic profile.
    • Enable the Internet access profile if your licensing and rollout plan require public internet and SaaS protection.
    • Assign the profile to the pilot users or groups you want to test first.
    Microsoft Global Secure Access

    Step 2: Enable Conditional Access signaling

    • In Global Secure Access, open Settings.
    • Select Session management.
    • Open the Adaptive Access tab.
    • Enable CA signaling so Global Secure Access network signals can be used by Conditional Access.
    • Save the setting and allow time for the change to become available in Conditional Access.

    Microsoft Global Secure AccessStep 3: Confirm the compliant network named location

    • After Conditional Access signaling is enabled, you should see the named location option called All Compliant Network Locations in Conditional Access. This location is used to identify traffic that is passing through Global Secure Access and is considered compliant for policy evaluation.

    Microsoft Global Secure AccessStep 4: Create a Conditional Access policy to require Global Secure Access

    This policy blocks access when users are not coming through the compliant Global Secure Access network. Use this carefully and test with a small pilot group first.

    1. Go to Microsoft Entra admin center > Protection > Conditional Access > Policies.
    2. Create a new policy.
    3. Under Users, select the test user or pilot group.
    4. Exclude emergency access or break-glass accounts.
    5. Under Target resources, select all cloud apps or limit the scope to apps such as Exchange Online and SharePoint Online.
    6. Under Conditions > Locations, include Any network or location.
    7. Exclude All Compliant Network Locations.
    8. Under Grant, select Block access.
    9. Start with Report-only mode if you are validating the effect, then turn the policy On after successful testing.
    10. Review the policy carefully and create it.
    Microsoft Global Secure Access

    Important production warning

    Do not apply a blocking Conditional Access policy to all users without testing. Always exclude emergency access accounts and validate with a small group before enforcing tenant-wide access control.

    If you want to learn more about recommended Conditional Access design, internally link this section to your existing article: Top 7 Conditional Access Policies.

    Step 5: Enable the Private Access profile

    If your goal is to provide secure access to internal resources such as a server, file share, RDP endpoint, or line-of-business application, configure the Private Access profile. If the profile is already enabled from previous testing, you can continue to the connector configuration.

    • Navigate to Global Secure Access.
    • Open Connect > Traffic forwarding.
    • Enable the Private Access profile.
    • Confirm the profile is assigned only to the pilot users or groups required for testing.

    Step 6: Download and install the private network connector

    • Under Global Secure Access, open Connect > Connectors and sensors.
    • Open the Private Network Connectors tab.
    • Select Download Connector Service.
    • Accept the terms and download the connector on the server that can reach the private resources.
    • Install the connector service.
    • Sign in with an account that has the required administrative permissions.
    • After installation, confirm the connector status shows Active.

    Microsoft Entra Private Access Configuration

    Step 7: Create or select a connector group

    After the connector is active, you can either use the default connector group or create a new connector group. A connector group helps you organize connectors that serve specific private resources, locations, or environments.

    • Go to Connectors and sensors.
    • Confirm the connector is Active.
    • Create a new connector group if you want to separate workloads by location or application.
    • Add the connector to the required connector group.

    Step 8: Configure Quick Access for private resources

    Quick Access is useful for testing access to private resources such as a server IP, internal web app, or RDP endpoint. In the original guide, the test scenario used a VM IP address and validated RDP access through Global Secure Access.

    • Open Global Secure Access > Applications.
    • Select Quick Access.
    • Open Network Access Properties.
    • Provide a meaningful name for the access group.
    • Select the connector group that contains the active private network connector.
    • Save the configuration.

    Microsoft Entra Private Entra Quick Access group

    Step 9: Add a Quick Access app segment

    • In Quick Access, select Add Quick Access App.
    • Enter the private resource details.
    • For testing, you can use a VM IP address, internal web app FQDN, or another private resource.
    • Specify the required port and protocol, such as TCP 3389 for RDP if testing remote desktop access.
    • Save the app segment.

    Application Segment.jpg

    Step 10: Assign users and groups to Private Access

    • Open the same Private Access or Quick Access application section.
    • Select Users and groups.
    • Add the pilot users or groups that need access to the private resource.
    • Avoid assigning all users during the initial test phase.
    • Save the assignment.

    Microsoft Global Secure Access


    How to download and install the Microsoft Global Secure Access client

    The Global Secure Access client is required when you want endpoint traffic to be acquired and forwarded based on the assigned traffic profiles. This is one of the most searched topics around Global Secure Access, so the article should include a dedicated section for client download, installation, and validation.

    • In the Microsoft Entra admin center, go to Global Secure Access.
    • Select Connect > Client download.
    • Choose the device platform you want to deploy.
    • Download the Global Secure Access client.
      Microsoft Global Secure Access
      • Install the client on a supported Microsoft Entra joined, hybrid joined, or supported registered device based on Microsoft requirements.
      • Make sure the user or deployment method has local administrator rights for installation.
      • After installation, sign in and confirm the client is connected.

      Global Secure Access Client

      End-user testing and expected behavior

      After the profiles, Conditional Access policy, connector, Quick Access segment, user assignment, and client installation are complete, validate the user experience. The original guide tested Microsoft 365 apps and access to a private VM through RDP.

      Test 1: Access Microsoft 365 and private resources while connected

      With the Global Secure Access client connected, test access to Microsoft 365 services such as Outlook, SharePoint, Teams, or OneDrive. Then test the private resource configured in Quick Access. In the original scenario, the private resource was a VM accessed using RDP.

      Global Secure Access RDP Access of Server

      Test 2: Disconnect the Global Secure Access client and test blocking behavior

      Next, disconnect the Global Secure Access client or test from a device that does not meet the compliant network requirement. If the Conditional Access policy is configured to block access outside compliant network locations, the user should receive a blocked access message.

      RDP access without Global Secure Access connectionEntra Private Access

      Expected result

      When the user is connected through Global Secure Access, access should succeed based on the configured policies. When the user is outside the compliant network path and the Conditional Access policy is enforced, access should be blocked.


      Monitoring Global Secure Access traffic

      Monitoring is important after the pilot is enabled. Use the Global Secure Access monitoring pages and Microsoft Entra logs to validate traffic flow, policy enforcement, and user impact.

      • Review Global Secure Access dashboards for traffic and usage visibility.
      • Check audit logs for configuration changes.
      • Review traffic logs to confirm whether traffic is forwarded, bypassed, allowed, or blocked.
      • Check Microsoft Entra sign-in logs for Conditional Access results.
      • Validate whether the compliant network condition is applied as expected.
      • Document successful and failed test cases before expanding rollout.

      Troubleshooting Microsoft Global Secure Access

      Use the following troubleshooting table as a quick reference during pilot and production rollout.

      Issue

      Possible Cause

      Recommended Fix

      User cannot access Microsoft 365

      Conditional Access policy blocks access because traffic is not recognized as compliant.

      Confirm client connection, profile assignment, and the All Compliant Network Locations exclusion.

      Global Secure Access client not connected

      Client not installed correctly, user not assigned, or device not supported.

      Verify device requirements, reinstall client, and confirm traffic profile assignment.

      Private resource not reachable

      Connector, connector group, app segment, port, or routing issue.

      Check connector health, app segment destination, protocol, port, and server reachability.

      No traffic logs visible

      Traffic profile not enabled or traffic not matching forwarding rules.

      Confirm traffic forwarding profile status and test with a supported destination.

      User receives blocked access message

      Policy is working, but scope may be too broad.

      Validate pilot scope, exclusions, and emergency access accounts.

      RDP fails through Private Access

      TCP 3389 not included or VM firewall blocks traffic.

      Confirm app segment, TCP port, Windows Firewall, and connector network path.

      Unexpected user impact after policy enforcement

      Policy applied to too many users or all cloud apps too early.

      Move policy to report-only, narrow user/app scope, and test again.


      Microsoft Global Secure Access vs VPN vs traditional Secure Web Gateway

      Capability

      Traditional VPN

      Traditional SWG

      Global Secure Access

      Access model

      Network-level access

      Web traffic inspection

      Identity-aware access to Microsoft 365, SaaS, internet, and private apps

      Zero Trust alignment

      Limited unless heavily customized

      Partial

      Strong integration with Microsoft Entra and Conditional Access

      Private app access

      Broad network access

      Not primary use case

      Per-app access through Entra Private Access

      Internet security

      Not designed for full internet security

      Core capability

      Available through Entra Internet Access

      Microsoft 365 protection

      Depends on routing and policies

      Depends on integration

      Microsoft traffic profile and compliant network checks

      User experience

      May add latency and broad tunneling

      Varies by provider

      Cloud-delivered and Microsoft-integrated

      Policy engine

      Network/security appliance rules

      Web/security rules

      Microsoft Entra Conditional Access and security policies


      Best practices for production rollout

      • Start with a small pilot group instead of all users.
      • Use report-only Conditional Access mode before enforcing block policies.
      • Exclude break-glass accounts from all restrictive policies.
      • Create separate policies for Microsoft traffic, internet access, and private access scenarios.
      • Document the expected user experience before rollout.
      • Deploy the Global Secure Access client using Intune for better control.
      • Use clear naming conventions for profiles, connector groups, app segments, and Conditional Access policies.
      • Monitor traffic logs, sign-in logs, and helpdesk tickets during the first rollout phase.
      • Keep rollback steps ready in case a policy causes unexpected access issues.

      Common mistakes to avoid

      • Applying a block policy to all users without excluding emergency access accounts.
      • Mixing Microsoft traffic, Internet Access, and Private Access explanations without separating the use cases.
      • Forgetting to assign users or groups to the traffic forwarding profile.
      • Installing the client but not confirming the user profile assignment.
      • Creating app segments without confirming port, protocol, and connector reachability.
      • Skipping traffic logs and sign-in logs during testing.
      • Assuming all Global Secure Access capabilities are included in the same license.

      Frequently Asked Questions

      What is Microsoft Global Secure Access?

      Microsoft Global Secure Access is Microsoft’s unified Security Service Edge solution in Microsoft Entra. It brings together Microsoft Entra Internet Access and Microsoft Entra Private Access to secure Microsoft 365, SaaS, internet, and private application access.

      Is Microsoft Global Secure Access the same as Microsoft Entra Internet Access?

      No. Global Secure Access is the broader unified term. Microsoft Entra Internet Access is one component focused on SaaS and internet traffic, while Microsoft Entra Private Access is focused on internal private resources.

      What license is required for Microsoft Global Secure Access?

      Licensing depends on the capability. The Microsoft traffic profile commonly requires Microsoft Entra ID P1 or P2. Full Internet Access and Private Access capabilities require the relevant standalone licenses or Microsoft Entra Suite.

      How do I download the Microsoft Global Secure Access client?

      Go to Microsoft Entra admin center > Global Secure Access > Connect > Client download. Select the required device platform and download the client.

      Does Global Secure Access replace VPN?

      Global Secure Access can reduce or replace broad VPN access for many private application scenarios when using Microsoft Entra Private Access. Organizations should test workloads carefully before replacing existing VPN services.

      How does Global Secure Access work with Conditional Access?

      Global Secure Access can provide network signals to Conditional Access. Admins can use compliant network locations to allow or block access based on whether traffic is routed through Global Secure Access.

      Can I use Global Secure Access for RDP access?

      Yes, Private Access can be configured with TCP app segments such as RDP if the connector, port, protocol, user assignment, and security policies are configured correctly.

      Should I enable Global Secure Access for all users immediately?

      No. Start with a pilot group, validate logs and user experience, then expand gradually.


      Final thoughts

      Microsoft Global Secure Access is becoming an important part of Microsoft Entra security architecture because it connects identity, network, endpoint, and Conditional Access controls in one Microsoft-managed access layer. For Microsoft 365 and Azure administrators, the best approach is to start with Microsoft traffic protection, validate client behavior, test Conditional Access compliant network policies, and then expand into Private Access or Internet Access based on the business requirement.

      The strongest version of this article is not just a product overview. It should be a practical implementation guide that shows the configuration, explains licensing, includes screenshots, demonstrates end-user behavior, and gives troubleshooting steps. That is what helps both readers and search engines understand that the content is useful, experience-based, and more valuable than a generic summary.


      Explore More From MS Cloud Explorers


      References and Further Reading


      Enjoyed the article?
      We’d love to hear your thoughts—share your comments below!
      For more insights, guides, and updates from the Microsoft ecosystem, be sure to subscribe to our newsletter and follow us on LinkedIn. Stay connected and never miss out on the latest tips and news!

      1 comment on “Microsoft Global Secure Access Explained: Licensing, Pricing, Client Download, and Setup Guide

      1. Really helpful summary! Global Secure Access seems like a big step forward for securing hybrid work. Thanks for making it easy to understand.

      Leave a Reply

      Your email address will not be published. Required fields are marked *