Microsoft Entra Global Secure Access

Create content policies for network content filtering

In brief

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

Create a content policy to filterpolicies for network file content filtering

Global Secure Access supports network content filtering through content policies. This feature helps you safeguard against unintended data exposure and prevents inline data leaks to generative AI applications and internet destinations. By extending data protection capabilities to the network layer through Global Secure Access, network content filtering enables your organization to enforce data policies on network traffic in real time. You can discover and protect files and text content shared with unsanctioned destinations, such as generative AI and unmanaged cloud apps, from managed endpoints through browsers, applications, add-ins, APIs, and more.

The network content filtering solution brings together Microsoft Purview's data classification service and the identity-centric network security policies in Global Secure Access. This combination creates an advanced network-layer data security solution, Data Loss Prevention (DLP), that's identity-centric and policy-driven. By combining content inspection with real-time user risk evaluation, you can enforce granular controls over sensitive data movement across the network without compromising user productivity or security posture.

High-level architecture

:::image type="content" source="media/how-to-network-content-filtering/network-content-filtering-architecture.png" alt-text="Diagram showing the architecture of network content filtering with Global Secure Access and Microsoft Purview." lightbox="media/how-to-network-content-filtering/network-content-filtering-architecture.png"::: This article explains how to create a content policy to filter internet traffic flowing through Global Secure Access.

Supported scenarios

Network content filtering supports the following key scenarios and outcomes for HTTP/1.1 traffic:

  • Using Basic content policy, you can block files based on supported file MIME types.
  • Using the Scan with Purview action (preview) in content policy, you can audit and block selected file and text content based on:
    • Microsoft Purview sensitivity labels
    • Sensitive content in files or text
    • The user's risk level
  • When you use Scan with Purview, you can generate Data Loss Prevention (DLP) admin alerts for rule matches.

Prerequisites

  • A valid Microsoft Entra tenant.
  • Licensing for the product. For details, see the licensing section of What is Global Secure Access. If needed, you can purchase licenses or get trial licenses.
    • A valid Microsoft Entra Internet Access license.
    • A valid Microsoft Purview license, required for Scan with Purview inspection.
      • You must set up pay-as-you-go billingNetwork data security requires Microsoft Purview pay-as-you-go billing to use Scan withbe configured before you create Purview collection or DLP policies. For more information, see Learn about Microsoft Purview billing models.
      • You can use basic content policy without a Purview license.
  • A user with the Global Secure Access Administrator role in Microsoft Entra ID to configure Global Secure Access settings.
  • A Conditional Access Administrator role to configure Conditional Access policies.
  • The Global Secure Access client requires a device (or virtual machine) that is either Microsoft Entra ID joined or Microsoft Entra ID Hybrid joined.
  • To use web categories as a content policy destination, you must also configure a web content filtering policy.
  • User Datagram Protocol (UDP) traffic (that is, QUIC) isn't supported. Most websites support fallback to Transmission Control Protocol (TCP) when QUIC can't be established. For an improved user experience, you can deploy a Windows Firewall rule that blocks outbound UDP 443:

Initial configuration

To configure content policies, complete the following initial setup steps:

  1. Enable the Internet Access traffic forwarding profile and ensure correct user assignments.
  2. Configure the Transport Layer Security (TLS) inspection policy.
  3. Install and configure the Global Secure Access client:
    1. Install the Global Secure Access client on Windows or macOS.
1. Select the **Global Secure Access** icon and select the Troubleshooting tab.
1. Under **Advanced Diagnostics**, select **Run tool**.
1. In the Global Secure Access Advanced Diagnostics window, select the **Forwarding Profile** tab.
1. Verify that **Internet Access** rules are present in the **Rules** section. This configuration might take up to 15 minutes to apply to clients after enabling the Internet Access traffic profile in the Microsoft Entra admin center.
    :::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::
  1. Confirm access to web applications you plan for content policies.

     - To use data policies configured in Microsoft Purview, select **Scan with Purview** (preview).
         :::image type="content" source="media/how-to-network-content-filtering/scan-with-purview.png" alt-text="Screenshot of the content rule screen with the Action menu expanded and the Scan with Purview option selected." lightbox="media/how-to-network-content-filtering/scan-with-purview.png":::
    
    1. For Matching conditions, select the appropriate Activities and Content types.
      • For basic content policy, select the file content types to allow or block.
      • For Scan with Purview, select the file content types and text content types that you want Microsoft Purview to inspect. File content type selection is optional for text-only scenarios. :::image type="content" source="media/how-to-network-content-filtering/content-rule-content-types.png" alt-text="Screenshot of the Add Content Rule page showing the Matching conditions section with Activities set to Upload, and the Content types dropdown expanded with PDF selected." lightbox="media/how-to-network-content-filtering/content-rule-content-types.png":::
    2. Select + Add destination and configure the destinations.
      • For application-specific control, you can add the exact URLs and related FQDNs that the app uses. Use browser developer tools or network traffic analysis to identify the endpoints used during file upload, text submission, or other protected traffic.
      • You can also select web categories as a destination. If you select web categories, you must also configure a web content filtering policy.
  2. Select Next.

  3. On the Review tab, review your settings.

  4. Select Create to create the policy.

Link the content policy to a security profile

  1. Select the security profile you want to modify.
  2. Switch to the Link policies view.
  3. Configure the link content policy:
    1. Select + Link a policy > Existing Content policy.
    2. From the Policy name menu, select the content policy you created.
    3. Keep the default values for Position and State.
    4. Select Add.
  4. Close the security profile.

Configure a Conditional Access policy

  1. Under Session, select Use Global Secure Access Security Profile and select the security profile you created.
  2. To create the policy, select Create.

For more information, see Create and link a Conditional Access policy.

The content policy is successfully configured.

Configure a Purview DLP policy for network data security

If you selected the Scan with Purview action in your content policy, you must configure a corresponding data loss prevention (DLP) policy in Microsoft Purview. The DLP policy defines how Purview classifies and acts on filesfile and text content that Global Secure Access routes for inspection.

Prerequisites for Purview integration

  • Microsoft Purview pay-as-you-go billing configured for your tenant. You must configure pay-as-you-go billing before you set up Microsoft Purview collection or DLP policies for network data security. For more information, see Learn about Microsoft Purview billing models.

For detailed steps on SASE provider integration, see Use Network Data Security to help prevent sharing sensitive information with unmanaged AI -- SASE provider integration.

Create a DLP policy for network data security

1. On the **Adaptive app scopes** tab, choose the app categories you want to protect against (for example, **All unmanaged AI apps**).
1. Select **Add**.
  1. Select Next.
  2. On the Choose where to enforce the policy page, ensure Network and non-Microsoft secure browsers is enabled, then select Next. You can only select Networknetwork enforcement when pay-as-you-go billing is set up. For more information, see Learn about Microsoft Purview billing models.
  3. Select Create or customize advanced DLP rules and select Next.
  4. Select + Create rule and configure the rule:
    1. Enter a Name and optional description.
    2. Under Conditions, select + Add condition > Content contains.
    3. Add the sensitive information types or sensitivity labels that match your organization's data protection requirements.
    4. Under Actions, select + Add an action > Restrict browser and network activities.
    5. Select the actions that match your content policy scenario and set each action to Audit or Block as appropriate:
      • Text sent to or shared with cloud or AI apps
      • Text received from cloud or AI apps
      • File uploaded to or shared with cloud or AI apps and set the action to
      • AuditFile downloaded from cloud or BlockAI apps as appropriate.
    6. Configure Incident reports and alert settings as needed.
    7. Select Save.
  5. Review the rule, ensure its status is On, and select Next.
  6. Select Next, review the policy, and select Submit.

For a detailed walkthrough with example configurations, see Use Network Data Security to help prevent sharing sensitive information with unmanaged AI.

Test the content policy

Test the configuration by attempting to upload or download filesfiles, or send text content, that matchmatches the content policy conditions. Verify that the policy settings blockaudit or allowblock the actions.

Example: Block sensitive text sent through Gmail

This example walks through an end-to-end test scenario that blocks text containing sensitive data, such as credit card numbers or Social Security numbers, from being sent in a Gmail message body.

Step 1: Configure the content policy destination

When you create or edit your content policy rule, configure the following settings:

  • Action: Select Scan with Purview (preview).
  • Activities: Select Upload.
  • Text content types: Select the text content types that you want Microsoft Purview to inspect.
  • Destination: Add mail.google.com as an FQDN.

For text-only scenarios, you don't need to select a file content type.

Step 2: Configure a Purview DLP policy

If you select Scan with Purview as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the text content and make the audit or block decision.

  1. In the Microsoft Purview portal, create an Inline web traffic DLP policy.
  2. On the Choose where to enforce the policy page, ensure Network and non-Microsoft secure browsers is enabled.
  3. Configure the DLP rule to detect the sensitive information types you want to block, such as credit card numbers or Social Security numbers.
  4. Under Actions, select Restrict browser and network activities.
  5. Select Text sent to or shared with cloud or AI apps and set the action to Block.
  6. Configure incident reports and alert settings as needed.
  7. Save and apply the policy.

Step 3: Validate the policy

  1. On a managed device with the Global Secure Access client installed, open a browser and go to Gmail.
  2. Create a message that contains sensitive data, such as sample credit card numbers or Social Security numbers.
  3. Attempt to send the message.
  4. Verify that the message is blocked.
  5. To confirm the block, check the traffic logs in the Microsoft Entra admin center under Global Secure Access > Monitor > Traffic logs.
  6. Review the corresponding alert or activity details in Microsoft Purview.

Example: Block sensitive PDF uploads to ChatGPT

  • https://chatgpt.com/backend-api/files/process_upload_stream (add as URL)
  • *.oaiusercontent.com (add as FQDN)

For Content types, select PDF (andand other file types you want to inspect).inspect.

Step 2: Configure a Purview DLP policy (for Scan with Purview action)

If you select Scan with Purview as the content policy action, you must also configure a corresponding Microsoft Purview DLP policy to inspect the file content and make the audit or block decision.

  1. Sign in to the Microsoft Purview portal.
  2. Follow the steps in Use Network Data Security to help prevent sharing sensitive information with unmanaged AI to create a new DLP policy.
    1. In the Cloud apps step, search for and add ChatGPT.
    2. Configure the DLP rule to detect the sensitive information types you want to block (for example, credit card numbers or Social Security numbers).

For more information about Purview DLP policies for network traffic, see Learn about Microsoft Purview Network Data Security.

Step 3: Validate the policy

Known limitations

  • Basic content policy doesn't inspect text. Text content type inspection requires Scan with Purview and a matching Purview DLP policy.
  • Network content filtering doesn't support User Datagram Protocol (UDP) traffic, including QUIC.
  • Compressed content is detected in ZIP format. The content isn't decompressed.
  • True file type detection might not be 100% accurate.
  • Top-level and second-level domains don't support wildcards (like *, *.com, *contoso.com) while configuring FQDNs.
  • Microsoft Purview network data security policies don't apply to B2B guest users.

Monitoring and logging