Microsoft Entra Private Access

Gsa Deployment Guide Private Access

In brief

1. Create end user communications to set expectations and provide an escalation path.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

  1. Create end user communications to set expectations and provide an escalation path.
  2. Create a roll-back plan that defines the circumstances and procedures for when you remove Global Secure Access client from a user device or disable the traffic forwarding profile.
  3. Create a Microsoft Entra groupCreate a Microsoft Entra group that includes your pilot users.
  4. Enable the Microsoft Entra Private Access traffic forwarding profile and assign your pilot group. Assign users and groups to traffic forwarding profiles.
  5. Provision servers or virtual machines that have line of sight access to your applications to function as connectors, providing outbound connectivity to applications for your users. Consider load balancing scenarios and capacity requirements for acceptable performance. Configure connectors for Microsoft Entra Private Access on each connector machine.
  6. If you have an inventory of enterprise applications, configure per-app access using Global Secure Access applications. If not, configure Quick Access for Global Secure Access.