Manage Private Access traffic forwarding profiles
In brief
Documentation now describes default and custom profiles, including profile settings, assignments, prerequisites, and a preview limit of 10 custom profiles.
What Entra admins need to know
Administrators can provide different private application access to specific users, devices, or groups. Application Administrator and Conditional Access Administrator roles, plus applicable licensing, are required to manage profiles.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
How to manage theManage Private Access traffic forwarding profileprofiles
Overview
The Private Access traffic forwarding profile routesprofiles route traffic to your private network throughfrom the Global Secure Access Client.client to private resources. Enabling this traffic forwarding profile allows remote workers to connect to internal resources without a VPN. With the features of Microsoft Entra Private Access, you can control which private resources to tunnel through the service and apply Conditional Access policies to secure access to those services. Once your configurations are in place,You can use the default Private Access profile or create custom profiles with different applications, assignments, device platforms, priorities, and status.
Multiple profiles let you can viewprovide different private application access to internal and manage all of those configurations from one place.external users, desktop and mobile devices, or other groups with distinct access requirements.
Prerequisites
To enable themanage Private Access traffic forwarding profile for your tenant,profiles, you must have:
- A Global Secure Access Administrator role in Microsoft Entra ID.
- An Application Administrator role to manage Private Access applications.
- A Conditional Access Administrator role to create and
interact withmanage Conditional Access policies.
Known limitations
[!INCLUDE known-limitations-include]
Enable the
During preview:
- You can create up to 10 custom Private Access traffic forwarding profiles.
- A Private Access application must be included in the default Private Access profile before it can be selected for a custom profile.
View Private Access profiles
- Sign in to the Microsoft Entra admin center as a
Global Secure Access Administrator.Global Secure Access Administrator. - Browse to Global Secure Access > Connect > Traffic forwarding.
The page displays the system-created profiles and any custom profiles. Select a profile name to manage its Basics, Acquisition rules, and Assignments.
To add a custom profile, see Create a Private Access traffic forwarding profile.
Manage profile settings
Select Basics to update the custom profile's name, description, priority, or status.
Priority determines which profile is effective if multiple Private Access profiles apply to the same user and device. Only the applicable profile with the highest priority is used by the client.
Manage acquisition rules
Acquisition rules determine which private resources are included in a profile.
Select the Private Access profile.
Select Acquisition rules.
Configure whether the profile includes Quick Access.
Select the applications link to add or remove Private Access applications.

Use Select all to include all available applications, and then remove the applications that shouldn't be part of the profile.
Associate an application with multiple profiles
You can also manage profile associations from the Private Access application:
- Browse to Global Secure Access > Applications > Enterprise applications.
- Select the
checkbox forapplication, and then selectPrivate Access profileNetwork access properties. - Select Manage attached profiles.
- Select one or more profiles, and then select Save.
Private Access policies
To enable theAn application can be associated with multiple Private Access traffic forwarding profile, it's recommendedprofiles.
Manage profile assignments
Select Assignments to first configure Quick Access. Quick Access includesconfigure:
User and device assignments: Assign no users or devices, all users and devices, or selected users, groups, and devices.
Device platform assignments: Select the
IP addresses, IP ranges, and fully qualified domain names (FQDNs) fordevice platforms that receive theprivate resources you want to include in the policy.profile.
The two assignment conditions are evaluated together. For more information, see Configure Quick Access.
You can also configure per-app access to your private resources by creatingexample, if a Private Access app. Similar to Quick Access, you create a new Enterprise app, which can then beprofile is assigned to selected users and the Private Access traffic forwardingAndroid platform, only Android devices used by those selected users receive the profile. Quick Access contains the main group of private resources you always want to route through the service. Private Access apps can be enabled and disabled as needed without impacting the FQDNs and IP addresses included in Quick Access.
To manage the details included in the Private Access traffic forwarding policy, select the View link for Private Access policies.

Details of your Quick AccessFor detailed steps and enterprise apps for Private Access are displayed. Select the link for the application to view the details from the Enterprise applications area of Microsoft Entra ID.assignment examples, see Assign users and devices to traffic forwarding profiles.
Linked Conditional Access policies
Conditional Access policies for Private Access are configured at the application level for each app.level. You can create and apply a Conditional Access policies can be created and applied to the applicationpolicy from two places:either location:
GoBrowse to Global Secure Access > Applications > Enterprise applications. Select anapplicationapplication, and then select Conditional Accessfrom the side menu..GoBrowse to Entra ID > Conditional Access > Policies. Select, and then select+ Create newNew policy.
For more information, see Apply Conditional Access policies to Private Access applications.
User and group assignmentsDelete a custom profile
You can scope theCustom Private Access profiles can be deleted. The system-created default profile to specific users and groups. The users and groups mustcan't be assigned to both the Private Access apps and the traffic forwarding profile.deleted. Deleted custom profiles can't be restored.
For more information about user and group assignment,detailed steps, see How to assign and manage users and groups with traffic forwarding profilesDelete a Private Access traffic forwarding profile.
Next steps
The next step for getting started with Microsoft Entra Internet Access is to install and configure the Global Secure Access Client on end-user devices.
For more information about Private Access, see the following articles:
@@ -1,71 +1,111 @@ ----title: How to Manage the Private Access Profile-description: "Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access."+title: Manage Private Access traffic forwarding profiles+description: Configure and manage default and custom Private Access traffic forwarding profiles in Global Secure Access. ms.topic: how-to-ms.date: 03/25/2026+ms.date: 09/20/2026 ms.subservice: entra-private-access ms.reviewer: katabish ai-usage: ai-assisted-ms.custom: sfi-image-nochange-# Customer intent: As an IT admin, I need to enable and manage the Private Access traffic forwarding profile so that the private access apps I configured can forward traffic according to the profile.+# Customer intent: As an IT admin, I need to manage Private Access traffic forwarding profiles so that the appropriate private applications are available to specific users and devices. --- -# How to manage the Private Access traffic forwarding profile+# Manage Private Access traffic forwarding profiles ## Overview -The Private Access traffic forwarding profile routes traffic to your private network through the Global Secure Access Client. Enabling this traffic forwarding profile allows remote workers to connect to internal resources without a VPN. With the features of Microsoft Entra Private Access, you can control which private resources to tunnel through the service and apply Conditional Access policies to secure access to those services. Once your configurations are in place, you can view and manage all of those configurations from one place.+Private Access traffic forwarding profiles route traffic from the Global Secure Access client to private resources. Enabling this traffic forwarding profile allows remote workers to connect to internal resources without a VPN. With the features of Microsoft Entra Private Access, you can control which private resources to tunnel through the service and apply Conditional Access policies to secure access to those services. You can use the default Private Access profile or create custom profiles with different applications, assignments, device platforms, priorities, and status.++Multiple profiles let you provide different private application access to internal and external users, desktop and mobile devices, or other groups with distinct access requirements. ## Prerequisites -To enable the Private Access forwarding profile for your tenant, you must have:+To manage Private Access traffic forwarding profiles, you must have: - A [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) role in Microsoft Entra ID.- - A [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role to create and interact with Conditional Access policies.-- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, you can [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).+- An [Application Administrator](../identity/role-based-access-control/permissions-reference.md#application-administrator) role to manage Private Access applications.+- A [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role to create and manage Conditional Access policies.+- Microsoft Entra Private Access or Microsoft Entra Suite licensing. For more information, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). ### Known limitations [!INCLUDE [known-limitations-include](../includes/known-limitations-include.md)] -## Enable the Private Access traffic forwarding profile+During preview:++- You can create up to 10 custom Private Access traffic forwarding profiles.+- A Private Access application must be included in the default Private Access profile before it can be selected for a custom profile.++## View Private Access profiles -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).+1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a Global Secure Access Administrator. 1. Browse to **Global Secure Access** > **Connect** > **Traffic forwarding**.-1. Select the checkbox for **Private Access profile**. -## Private Access policies+The page displays the system-created profiles and any custom profiles. Select a profile name to manage its **Basics**, **Acquisition rules**, and **Assignments**. -To enable the Private Access traffic forwarding profile, it's recommended to first configure Quick Access. Quick Access includes the IP addresses, IP ranges, and fully qualified domain names (FQDNs) for the private resources you want to include in the policy. For more information, see [Configure Quick Access](how-to-configure-quick-access.md).+To add a custom profile, see [Create a Private Access traffic forwarding profile](how-to-create-traffic-forwarding-profile.md). -You can also configure per-app access to your private resources by creating a Private Access app. Similar to Quick Access, you create a new Enterprise app, which can then be assigned to the Private Access traffic forwarding profile. Quick Access contains the main group of private resources you always want to route through the service. Private Access apps can be enabled and disabled as needed without impacting the FQDNs and IP addresses included in Quick Access.+## Manage profile settings -To manage the details included in the Private Access traffic forwarding policy, select the **View** link for **Private Access policies**. +Select **Basics** to update the custom profile's name, description, priority, or status. -+Priority determines which profile is effective if multiple Private Access profiles apply to the same user and device. Only the applicable profile with the highest priority is used by the client. -Details of your Quick Access and enterprise apps for Private Access are displayed. Select the link for the application to view the details from the Enterprise applications area of Microsoft Entra ID.+## Manage acquisition rules -## Linked Conditional Access policies+Acquisition rules determine which private resources are included in a profile. -Conditional Access policies for Private Access are configured at the application level for each app. Conditional Access policies can be created and applied to the application from two places:+1. Select the Private Access profile.+1. Select **Acquisition rules**.+1. Configure whether the profile includes Quick Access.+1. Select the applications link to add or remove Private Access applications. -- Go to **Global Secure Access** > **Applications** > **Enterprise applications**. Select an application and then select **Conditional Access** from the side menu.-- Go to **Entra ID** > **Conditional Access** > **Policies**. Select **+ Create new policy**.+  -For more information, see [Apply Conditional Access policies to Private Access apps](how-to-target-resource-private-access-apps.md).+Use **Select all** to include all available applications, and then remove the applications that shouldn't be part of the profile. -## User and group assignments-You can scope the Private Access profile to specific users and groups. The users and groups must be assigned to both the Private Access apps and the traffic forwarding profile.+### Associate an application with multiple profiles -For more information about user and group assignment, see [How to assign and manage users and groups with traffic forwarding profiles](how-to-manage-users-groups-assignment.md).+You can also manage profile associations from the Private Access application: +1. Browse to **Global Secure Access** > **Applications** > **Enterprise applications**.+1. Select the application, and then select **Network access properties**.+1. Select **Manage attached profiles**.+1. Select one or more profiles, and then select **Save**. +An application can be associated with multiple Private Access traffic forwarding profiles. -## Next steps+## Manage profile assignments++Select **Assignments** to configure:++- **User and device assignments**: Assign no users or devices, all users and devices, or selected users, groups, and devices.+- **Device platform assignments**: Select the device platforms that receive the profile.++ ++The two assignment conditions are evaluated together. For example, if a profile is assigned to selected users and the Android platform, only Android devices used by those selected users receive the profile.++For detailed steps and assignment examples, see [Assign users and devices to traffic forwarding profiles](how-to-manage-users-groups-assignment.md). -The next step for getting started with Microsoft Entra Internet Access is to [install and configure the Global Secure Access Client on end-user devices](how-to-install-windows-client.md).+## Linked Conditional Access policies++Conditional Access policies for Private Access are configured at the application level. You can create and apply a Conditional Access policy from either location:++- Browse to **Global Secure Access** > **Applications** > **Enterprise applications**. Select an application, and then select **Conditional Access**.+- Browse to **Entra ID** > **Conditional Access** > **Policies**, and then select **New policy**.++For more information, see [Apply Conditional Access policies to Private Access applications](how-to-target-resource-private-access-apps.md).++## Delete a custom profile++Custom Private Access profiles can be deleted. The system-created default profile can't be deleted. Deleted custom profiles can't be restored.++For detailed steps, see [Delete a Private Access traffic forwarding profile](how-to-delete-traffic-forwarding-profile.md).++## Next steps -For more information about Private Access, see the following articles:-- [Learn about traffic forwarding](concept-traffic-forwarding.md)+- [Create a Private Access traffic forwarding profile](how-to-create-traffic-forwarding-profile.md)+- [Delete a Private Access traffic forwarding profile](how-to-delete-traffic-forwarding-profile.md)+- [Assign users and devices to traffic forwarding profiles](how-to-manage-users-groups-assignment.md) - [Configure Quick Access](how-to-configure-quick-access.md)+- [Install and configure the Global Secure Access client](how-to-install-windows-client.md) 