Global Secure Access and Universal Tenant Restrictions
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra Global Secure Access.
Microsoft Learn documentation ↗Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).
Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.
You can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge by using an Intune mobile application management (MAM) policy. The policy can take advantage of the Explicit Forward Proxy feature of Global Secure Access.
Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:
Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).
- [Global Secure Access traffic forwarding profiles](concept-traffic-forwarding.md)
- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time.
Learn how to configure universal tenant restrictions with Global Secure Access for Microsoft traffic.
Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.
Learn how to configure a Conditional Access policy that requires a compliant network with Global Secure Access.
Learn how to enable the Microsoft traffic profile in Global Secure Access, assign users, install the client, and verify traffic forwarding.
Learn about Microsoft traffic labs for Global Secure Access, including source IP restoration, compliant network checks, and universal tenant restrictions.
Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
Calculate the Microsoft Sentinel alert noise ratio for Global Secure Access detections and send an alert when false positives or informational closures exceed your threshold.
Check Global Secure Access-related administrator role assignments and identify accounts that need quarterly review.
List Microsoft Entra Backup and Recovery snapshots that can help recover directory objects used by Global Secure Access.
Create a non-destructive Microsoft Entra recovery preview job scoped to directory objects that affect Global Secure Access.
Run a Microsoft Entra recovery job for directory objects that affect Global Secure Access after reviewing a recovery preview.
Use shared helper functions for authentication and alert email in Global Secure Access operations automation scripts.
Verify that your Global Secure Access configuration backup runbook ran successfully. Send an alert when the runbook fails or misses a scheduled run.
Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.
- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)
1. Create end user communications to set expectations and provide an escalation path.
- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)
- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)
Learn how AI agent discovery in Global Secure Access provides network-level visibility into managed and shadow AI agents reaching the internet from your environment.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Use Application discovery to detect the applications accessed by users and create separate private applications.
Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.
Learn how to configure a Conditional Access policy for Explicit Forward Proxy.
Learn how to configure HTTP header session management for Explicit Forward Proxy.
A Microsoft Entra documentation page was updated: Configure Microsoft Edge with Explicit Forward Proxy (preview) by using an Intune application management policy.
Learn how to configure Secure Web and AI Gateway for Microsoft Copilot Studio agents using Global Secure Access.
Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Learn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.
Learn how to set up the bidirectional communication tunnel between Global Secure Access and your router.
The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the macOS client.
Use Global Secure Access to configure Azure and Microsoft Entra resources to create a virtual wide area network to connect to your resources in Azure.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.
This article provides techniques to improve remote network resilience with Global Secure Access.
Learn about Explicit Forward Proxy session management concepts.
Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.
Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.
Global Secure Access maintains a compliance portfolio. This article lists the current, supported certifications.
Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.
Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
Learn how to add and delete customer premises equipment device links to remote networks for Global Secure Access.
Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.
Learn how to monitor and troubleshoot remote network connectivity using Microsoft Entra Health monitoring.
Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
A Microsoft Entra documentation page was updated: Install Android Client.
The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the Windows client.
Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.
Learn about Explicit Forward Proxy PAC file concepts.
Understand critical IP address ranges to consider when configuring and troubleshooting internet over remote network connectivity.
Discover the known limitations of Global Secure Access, including platform-specific issues and mitigations, to ensure seamless deployment and management.
Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.
Learn how Global Secure Access enables secure external user access for partners through the Global Secure Access client and Azure Virtual Desktop.
Learn about the features and benefits of our Secure Web and AI Gateway for agents in Global Secure Access.
This article tracks the release notes and download instructions for the Global Secure Access client for macOS.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Install the Global Secure Access Windows client as a proof of concept. This script automates installation and applies essential configurations.
Learn how Shadow AI discovery in Global Secure Access provides network-based visibility into unsanctioned AI applications and tools used in your organization.
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
This document provides troubleshooting guidance for the Global Secure Access client when it shows the "disabled by your organization" error message.
Troubleshoot the macOS Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
ai-usage: ai-assisted
Reduce risk from malicious or manipulated prompts sent to generative AI sites and apps with prompt injection protection policies in Global Secure Access.
Learn if a device can communicate with the Global Secure Access service and tunnel traffic, by using the health check utility.
Learn how to troubleshoot and resolve Transport Layer Security (TLS) inspection errors in Global Secure Access.
Learn about Universal Continuous Evaluation concepts
This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
:::image type="content" source="media/concept-external-user-access/guest-access-overview.png" alt-text="Diagram showing an overview of external user access in Global Secure Access." lightbox="media/concept-external-user-access/guest-access-overview.png":::
@{ Key="HKLM:\SOFTWARE\Policies\Microsoft\Edge"; Name="BuiltInDnsClientEnabled"; Type="DWord"; Value=0 },
When you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.
For usage in US Government community (GCC) cloud, known limitations/disclaimers include:
This section is organized in the order you should implement monitoring for Microsoft traffic:
- **Platform operations and monitoring engineers** who manage health checks, automation, and dashboards
During the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.
Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).
> The Explicit Forward Proxy feature is currently in PREVIEW.
Explicit Forward Proxy (EFP) is one of the traffic acquisition mechanisms that's useful in scenarios where installation of the Global Secure Access (GSA) client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from:
A PAC file is a mechanism used to automatically determine which proxy server a web browser or application should use for a given request. PAC files are an integral part of Explicit Forward Proxy configuration, enabling flexible and dynamic traffic steering decisions. In the context of Global Secure Access, PAC files are similar to the traffic forwarding policies of the GSA client.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, and TLS certificate creation.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).
Use Application discovery to detect the applications accessed by users and create separate private applications.
**Q: Is this feature supported from a windows Entra registered device(BYOD)?**