# userimpact: Low
# implementationcost: Medium
---
Comprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. When the Global Secure Access client isn't deployed to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.
Without the Global Secure Access client:
- Devices can't benefit from compliant network checks in Conditional Access policies, source IP restoration, or tenant restrictions.
- Credential theft and token replay attacks become more difficult to detect when traffic bypasses the security perimeter.
- Managed endpoints can't access private applications through Microsoft Entra Private Access.
**Remediation action**
- Install the Global Secure Access client:
- [Windows](/entra/global-secure-access/how-to-install-windows-client).
- [macOS](/entra/global-secure-access/how-to-install-macos-client)
- [iOS](/entra/global-secure-access/how-to-install-ios-client)
- [Android](/entra/global-secure-access/how-to-install-android-client)
- Monitor the the Global Secure Access client health and connection status with the [Global Secure Access dashboard](/entra/global-secure-access/concept-traffic-dashboard).
# userimpact: Low
# implementationcost: Medium
---
Comprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. If you don't deploy the Global Secure Access client to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.
Without the Global Secure Access client:
- Devices can't benefit from compliant network checks in Conditional Access policies, source IP restoration, or tenant restrictions.
- Credential theft and token replay attacks are more difficult to detect when traffic bypasses the security perimeter.
- Managed endpoints can't access private applications through Microsoft Entra Private Access.
**Remediation action**
- Install the Global Secure Access client:
- [Windows client](/entra/global-secure-access/how-to-install-windows-client)
- [macOS client](/entra/global-secure-access/how-to-install-macos-client)
- [iOS client](/entra/global-secure-access/how-to-install-ios-client)
- [Android client](/entra/global-secure-access/how-to-install-android-client)
- Monitor the Global Secure Access client health and connection status by using the [Global Secure Access dashboard](/entra/global-secure-access/concept-traffic-dashboard).