Microsoft Entra Global Secure Access

Operations

In brief

| Guide | What it covers |

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Guide What it covers
Common operations RACI matrix (responsible, accountable, consulted, informed) for roles and responsibilities, change management process, metrics and reporting framework, continuous improvement
Security operations for network accessSecurity monitoring, detection patterns, Sentinel analytics rules, and cross-signal investigation guidance for Global Secure Access

Capability-specific operations

If you completed deployment, follow this sequence:

  1. Establish your team—Assign roles using the RACI matrix. Ensure at least two people cover each role.
  2. Configure alerting—Set up the critical alerts listed in the Security operations for network access guide and each capability guide: Private Access, Internet Access, Remote Networks, and Microsoft Traffic. Don't rely on dashboards for issue detection.
  3. Establish baselines—Collect a 30-day performance baseline for traffic volume, latency, and usage. Calibrate alert thresholds against this baseline. Each capability guide includes Kusto Query Language (KQL) queries for baseline establishment.
  4. Set up automation—Start with configuration backups and alert notifications. Expand to the full automation playbook list over time.
  5. Schedule recurring checks—Implement the daily, weekly, and monthly checklists from each capability guide.