Assign users and devices to traffic forwarding profiles
In brief
The article now documents assigning users, groups, devices, and device platforms to traffic forwarding profiles, including custom Private Access profiles. It also explains that user/device and platform conditions are evaluated together and that the highest-priority applicable profile is used.
What Entra admins need to know
Administrators can use these assignment rules to scope traffic forwarding more precisely across users and devices.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
How to assignAssign users and groupsdevices to traffic forwarding profiles
Overview
With theYou can assign specific users, groups, devices, and device platforms to a Global Secure Access traffic forwarding features,profile. Assignments let you can assign specificdeploy a profile gradually and provide different traffic acquisition rules to different users and groups to a traffic forwarding profile. User or group assignment limits the scope of the traffic forwarding profile so you have a mechanism to roll out the profile safely and at a controlled pace.devices.
This article describes how to assign specific users and groups to aexplains assignments for traffic forwarding profile.profiles, including custom Private Access profiles.
Prerequisites
To assign a traffic forwarding profile to specific users and groups,manage assignments, you must have:
- A Global Secure Access Administrator role in Microsoft Entra ID to view and manage the traffic forwarding profile.
An Application Administrator role to assign the traffic profile to the selected users and groups.- The
product requires licensing. For details, see the licensing section of What is Global Secure Access. If needed, you can purchase licenses or get trial licenses. The minimumrequired Global Secure Access product licenses. For details, see What is Global Secure Access.- The latest supported Global Secure Access client on applicable devices. The minimum client version for user and group assignment is 1.7.376.0.
Clients below this version won't receive the
How assignments are evaluated
A traffic forwarding profile when assigned to the user.
Assign a traffic forwarding profile to specific users and groups
If you already enabled a traffic forwarding profile, the traffic profile is assigned to all users by default. If you haven't yet enabled a traffic forwarding profile, when you enable it the traffic is assigned to zero users. The has two assignment conditions:
- User and
groupdevice assignmentssetting lets you roll outdetermine which users, groups, or individual devices are in scope. - Device platform assignments determine which device platforms are in scope.
The conditions are evaluated with an AND. A device receives a profile only when it matches both conditions.
If multiple enabled profiles for the feature in a controlled mannersame traffic type apply to a specific set of users.
The screenshot illustrates the setting. The Microsoft profile is disabled and is assigned to zero users and groups. The Private Access and Internet Access profiles are enabled and are assigned to all users.
:::image type="content" source="media/how-to-manage-users-groups-assignment/traffic-profile-user-assignment-comparison.png" alt-text="Screenshot of the traffic forwarding page with user assignments highlighted." lightbox="media/how-to-manage-users-groups-assignment/traffic-profile-user-assignment-comparison-expanded.png":::
You can configure the user and group assignments before or after enablingdevice, only the traffic profile. You must enableapplicable profile with the traffic profile to acquirehighest priority is used.
Assign users, groups, and forward any traffic. For more information, see About traffic forwarding profiles.Assign users and groups to a traffic profile
devices
Sign in to the Microsoft Entra admin center as a
Global Secure Access Administrator AND Application Administrator.Global Secure Access Administrator and Application Administrator.Browse to Global Secure Access > Connect > Traffic forwarding.
Select the
Viewlink in theUser and group assignmentssection.
Select the0 Users, 0 Groups assignedlink.traffic forwarding profile.
Select
Add user/groupAssignments.
Select theNone selectedlink, select the users and/or groups from the list, and select theSelectbutton.TheAlllist groups users and groups together. Select either theUsersorGroupstabNext tonarrow the list.You can also use the Search box to find the user or group directly.

Select theAssignbutton.
Change existing user and group assignments
The process to change the user and group assignments for a traffic profile that's already enabled is very similar except for the following steps.
When you select theViewlink in theUser andgroupdevice assignmentssection, you need to change the, selectAssign to all userssetting toNo.
Review the confirmation message, and select theOKbutton.
Continue with the steps in the previous section.
Automatic assignment through user attributes
You can create and assign a dynamic group of users to the profile who satisfy specific criteria. For more information about automatic assignment using user attributes, see Create or update a dynamic group in Microsoft Entra ID.
Assign the traffic profile to all users
Once you assign a traffic forwarding profile to a specific user or group, you can quickly change the setting to scope the traffic profile to all users. If you change it back again to a specific group, any users and groups initially assigned to that traffic forwarding profile are retained so you don't need to add them again.
Browse toGlobal Secure Access>Connect>Traffic forwardingView.Select one of the following options:
ViewNo users and deviceslink: The profile isn't assigned through the Global Secure Access client.- All users and devices: All devices with the Global Secure Access client are in scope, subject to the device-platform assignment.
userSelected users andgroup assignmentsdevicessection.: Select specific users, groups, or devices.
Change theIf you selectedAssign to allSelected userstoggle toYesand devices,review the confirmation message, andselect theOKbutton.
Selectassignment link, choose theDonebutton.
Revert all users assignment back to a specific user or group
You can revert the assignment of all users to a traffic profile. When you toggle off the assignment for all users, you revert to the usersgroups, and groups that were assigned when you toggled it on.
Browse todevices, and then selectGlobal Secure Access>Connect>Traffic forwardingSelect.Select
theViewlink in theuser and group assignmentssection.Change theAssign to all userstoggle toNo, review the confirmation message, and select theOKbutton.SelectDoneSave.
Notes on user identity and groupAssign device platforms
- From the profile's Assignments page, select View next to Device platform assignments.
- Select the device platforms that should receive the profile.
- Select Save.
You can combine platform assignment
Review the following notes to better understand the with user and device assignment. For example:
- Assign All users and devices and select iOS to apply the profile to all iOS devices with the Global Secure Access client.
- Assign a user group and select Windows and macOS to apply the profile only to desktop devices used by members of that group.
Assignment evaluation examples
| User and device assignments | Device platform assignments | Result |
|---|---|---|
| All users and devices | All device platforms | All devices with the Global Secure Access client receive the profile. |
| All users and devices | Windows and macOS | All Windows and macOS devices with the client receive the profile. |
| All users and devices | None | No devices receive the profile. |
| Five users and two devices | All device platforms | All client devices used by the five users and the two selected devices receive the profile. |
| Five users and two devices | Android | Android client devices used by the five users and the selected devices receive the profile only if those devices are Android devices. |
| No users, groups, or devices | Any platform | No devices receive the profile. |
Assign a profile to all devices on a platform
To assign a profile to all devices on a specific platform:
- Set User and device assignments to All users and devices.
- Under Device platform assignments, select only the target platform.
- Save both assignment
capabilities.settings.
Automatic assignment through user attributes
You can assign a dynamic group whose members satisfy specific user criteria. For more information, see Create or update a dynamic group in Microsoft Entra ID.
Validate the effective profile
- Sign in to a registered device as a user included in the assignment.
- Right-click the Global Secure Access client, and then select Advanced diagnostics > Forwarding profile.
- Expand the applicable traffic type, such as Private Access rules.
- Confirm that the expected application segments appear.
If more than one profile could apply, confirm that the profile with the highest priority is effective.
Notes about identity, groups, and devices
- Traffic profiles are fetched
on behalf offor the Microsoft Entra userlogged intosigned in to thedevice,device, not the userlogged intosigned in to theclient.client. - If
there'sno Microsoft Entra userloggedis signed in,the traffica profile is fetched onlyif it's assigned to all users. For example, if you log into the device as a local admin you're part of the all users.when All users and devices is selected. - Multiple users
logging intosigned in to the same device simultaneouslyisnaren't supported. Group-basedGroup assignmentis supported for Securitysupports security groups andMicrosoft 365 groups whoseSecurityEnabledsettingnested group membership isset toTrue.Nested group memberships aren'tsupported.A user must be a direct member of the group assigned to the profile.
Next steps
@@ -1,117 +1,107 @@ ----title: Assign users and groups to traffic forwarding profiles-description: "Control which users and groups receive traffic forwarding policies, enabling gradual rollout and limiting scope during testing or deployment phases."+title: Assign users and devices to traffic forwarding profiles+description: Assign users, groups, devices, and device platforms to Global Secure Access traffic forwarding profiles. ms.topic: how-to-ms.date: 05/26/2026+ms.date: 09/20/2026 ai-usage: ai-assisted ----# How to assign users and groups to traffic forwarding profiles+# Assign users and devices to traffic forwarding profiles ## Overview -With the Global Secure Access traffic forwarding features, you can assign specific users and groups to a traffic forwarding profile. User or group assignment limits the scope of the traffic forwarding profile so you have a mechanism to roll out the profile safely and at a controlled pace.+You can assign specific users, groups, devices, and device platforms to a Global Secure Access traffic forwarding profile. Assignments let you deploy a profile gradually and provide different traffic acquisition rules to different users and devices. -This article describes how to assign specific users and groups to a traffic forwarding profile.+This article explains assignments for traffic forwarding profiles, including custom Private Access profiles. ## Prerequisites -To assign a traffic forwarding profile to specific users and groups, you must have:+To manage assignments, you must have: -- A [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) role in Microsoft Entra ID to view the traffic forwarding profile.-- An [Application Administrator](../identity/role-based-access-control/permissions-reference.md#application-administrator) role to assign the traffic profile to the selected users and groups.-- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, you can [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).-- The minimum required Global Secure Access client version is 1.7.376.0. Clients below this version won't receive the traffic forwarding profile when assigned to the user.+- A [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) role in Microsoft Entra ID to view and manage the traffic forwarding profile.+- The required Global Secure Access product licenses. For details, see [What is Global Secure Access](overview-what-is-global-secure-access.md).+- The latest supported Global Secure Access client on applicable devices. The minimum client version for user and group assignment is 1.7.376.0. -## Assign a traffic forwarding profile to specific users and groups+## How assignments are evaluated -If you already enabled a traffic forwarding profile, the traffic profile is assigned to all users by default. If you haven't yet enabled a traffic forwarding profile, when you enable it the traffic is assigned to zero users. The **User and group assignments** setting lets you roll out the feature in a controlled manner to a specific set of users.+A traffic forwarding profile has two assignment conditions: -The screenshot illustrates the setting. The Microsoft profile is disabled and is assigned to zero users and groups. The Private Access and Internet Access profiles are enabled and are assigned to all users.+- **User and device assignments** determine which users, groups, or individual devices are in scope.+- **Device platform assignments** determine which device platforms are in scope. -:::image type="content" source="media/how-to-manage-users-groups-assignment/traffic-profile-user-assignment-comparison.png" alt-text="Screenshot of the traffic forwarding page with user assignments highlighted." lightbox="media/how-to-manage-users-groups-assignment/traffic-profile-user-assignment-comparison-expanded.png":::+The conditions are evaluated with an `AND`. A device receives a profile only when it matches both conditions. -You can configure the user and group assignments before or after enabling the traffic profile. You must enable the traffic profile to acquire and forward any traffic. For more information, see [About traffic forwarding profiles](concept-traffic-forwarding.md).+If multiple enabled profiles for the same traffic type apply to a user and device, only the applicable profile with the highest priority is used. -### Assign users and groups to a traffic profile--1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) AND [Application Administrator](../identity/role-based-access-control/permissions-reference.md#application-administrator).+## Assign users, groups, and devices +1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a Global Secure Access Administrator and Application Administrator. 1. Browse to **Global Secure Access** > **Connect** > **Traffic forwarding**.+1. Select the traffic forwarding profile.+1. Select **Assignments**.+1. Next to **User and device assignments**, select **View**.+1. Select one of the following options: -1. Select the **View** link in the **User and group assignments** section.-- --1. Select the **0 Users, 0 Groups assigned** link.-- --1. Select **Add user/group**.-- --1. Select the **None selected** link, select the users and/or groups from the list, and select the **Select** button.- - The **All** list groups users and groups together. Select either the **Users** or **Groups** tab to narrow the list.- - You can also use the Search box to find the user or group directly.-- --1. Select the **Assign** button.+ - **No users and devices**: The profile isn't assigned through the Global Secure Access client.+ - **All users and devices**: All devices with the Global Secure Access client are in scope, subject to the device-platform assignment.+ - **Selected users and devices**: Select specific users, groups, or devices. -### Change existing user and group assignments+  -The process to change the user and group assignments for a traffic profile that's already enabled is very similar except for the following steps.+1. If you selected **Selected users and devices**, select the assignment link, choose the users, groups, and devices, and then select **Select**.+1. Select **Save**. -1. When you select the **View** link in the **User and group assignments** section, you need to change the **Assign to all users** setting to **No.**+## Assign device platforms - +1. From the profile's **Assignments** page, select **View** next to **Device platform assignments**.+1. Select the device platforms that should receive the profile.+1. Select **Save**. -1. Review the confirmation message, and select the **OK** button.+You can combine platform assignment with user and device assignment. For example: - +- Assign **All users and devices** and select **iOS** to apply the profile to all iOS devices with the Global Secure Access client.+- Assign a user group and select **Windows** and **macOS** to apply the profile only to desktop devices used by members of that group. -1. Continue with the steps in the previous section.+## Assignment evaluation examples -### Automatic assignment through user attributes+| User and device assignments | Device platform assignments | Result |+| --- | --- | --- |+| All users and devices | All device platforms | All devices with the Global Secure Access client receive the profile. |+| All users and devices | Windows and macOS | All Windows and macOS devices with the client receive the profile. |+| All users and devices | None | No devices receive the profile. |+| Five users and two devices | All device platforms | All client devices used by the five users and the two selected devices receive the profile. |+| Five users and two devices | Android | Android client devices used by the five users and the selected devices receive the profile only if those devices are Android devices. |+| No users, groups, or devices | Any platform | No devices receive the profile. | -You can create and assign a dynamic group of users to the profile who satisfy specific criteria. For more information about automatic assignment using user attributes, see [Create or update a dynamic group in Microsoft Entra ID](../identity/users/groups-create-rule.md).+## Assign a profile to all devices on a platform -## Assign the traffic profile to all users+To assign a profile to all devices on a specific platform: -Once you assign a traffic forwarding profile to a specific user or group, you can quickly change the setting to scope the traffic profile to all users. If you change it back again to a specific group, any users and groups initially assigned to that traffic forwarding profile are retained so you don't need to add them again. +1. Set **User and device assignments** to **All users and devices**.+1. Under **Device platform assignments**, select only the target platform.+1. Save both assignment settings. -1. Browse to **Global Secure Access** > **Connect** > **Traffic forwarding**.--1. Select the **View** link in the **user and group assignments** section.--1. Change the **Assign to all users** toggle to **Yes**, review the confirmation message, and select the **OK** button.-- --1. Select the **Done** button.--### Revert all users assignment back to a specific user or group--You can revert the assignment of all users to a traffic profile. When you toggle off the assignment for all users, you revert to the users and groups that were assigned when you toggled it on.--1. Browse to **Global Secure Access** > **Connect** > **Traffic forwarding**.+## Automatic assignment through user attributes -1. Select the **View** link in the **user and group assignments** section.+You can assign a dynamic group whose members satisfy specific user criteria. For more information, see [Create or update a dynamic group in Microsoft Entra ID](../identity/users/groups-create-rule.md). -1. Change the **Assign to all users** toggle to **No**, review the confirmation message, and select the **OK** button.+## Validate the effective profile -1. Select **Done**. +1. Sign in to a registered device as a user included in the assignment.+1. Right-click the Global Secure Access client, and then select **Advanced diagnostics** > **Forwarding profile**.+1. Expand the applicable traffic type, such as **Private Access rules**.+1. Confirm that the expected application segments appear. -## Notes on user identity and group assignment+If more than one profile could apply, confirm that the profile with the highest priority is effective. -Review the following notes to better understand the user and group assignment capabilities.+## Notes about identity, groups, and devices -- Traffic profiles are fetched on behalf of the Microsoft Entra user logged into the device, not the user logged into the client. -- If there's no Microsoft Entra user logged in, the traffic profile is fetched only if it's assigned to all users. For example, if you log into the device as a local admin you're part of the all users.-- Multiple users logging into the same device simultaneously isn't supported.-- Group-based assignment is supported for Security groups and Microsoft 365 groups whose `SecurityEnabled` setting is set to `True`.-- Nested group memberships aren't supported. A user must be a direct member of the group assigned to the profile. +- Traffic profiles are fetched for the Microsoft Entra user signed in to the device, not the user signed in to the client.+- If no Microsoft Entra user is signed in, a profile is fetched only when **All users and devices** is selected.+- Multiple users signed in to the same device simultaneously aren't supported.+- Group assignment supports security groups and nested group membership is supported. ## Next steps +- [Create a Private Access traffic forwarding profile](how-to-create-traffic-forwarding-profile.md)+- [Manage Private Access traffic forwarding profiles](how-to-manage-private-access-profile.md) - [Learn about Global Secure Access clients](concept-clients.md) 