Product

Microsoft Entra Global Secure Access

Track documentation and Message Center changes for Microsoft Entra Global Secure Access.

Microsoft Learn documentation ↗

Latest Microsoft Entra Global Secure Access changes

Configure Per App Access

Microsoft identity platform

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

Global Secure Access egress IP ranges

General

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

Configure Web Content Filtering

General

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

Universal Tenant Restrictions

Authentication

- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.

Configure HTTP header session management (preview)

Authentication

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

Explicit Forward Proxy overview

Fundamentals

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

Explicit Forward Proxy session management

Fundamentals

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Proxy Automatic Configuration Files

Fundamentals

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

Configure Web Content Filtering

General

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

Tutorial: Enable source IP restoration

Authentication

Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.

PowerShell samples for Global Secure Access

Monitoring

Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.

Security Operations

Security

- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)

Operations

Fundamentals

| Guide | What it covers |

Universal Tenant Restrictions

General

- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)

Universal Tenant Restrictions

General

- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)

Ai Prompt Injection Protection

Security

Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.

Application Discovery

Developer

Use Application discovery to detect the applications accessed by users and create separate private applications.

Application Usage Analytics Overview

Fundamentals

Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.

Export Connector Logs

Monitoring

Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.

How to Create Remote Networks

General

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

Install Android Client

General

A Microsoft Entra documentation page was updated: Install Android Client.

Install Ios Client

General

A Microsoft Entra documentation page was updated: Install Ios Client.

Install Windows Client

General

The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the Windows client.

Known Limitations for Global Secure Access

General

Discover the known limitations of Global Secure Access, including platform-specific issues and mitigations, to ensure seamless deployment and management.

Learn about Global Secure Access Alerts

Fundamentals

Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.

Macos Client Release History

General

This article tracks the release notes and download instructions for the Global Secure Access client for macOS.

Network Content Filtering

Security

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.

Shadow AI discovery in Global Secure Access

Fundamentals

Learn how Shadow AI discovery in Global Secure Access provides network-based visibility into unsanctioned AI applications and tools used in your organization.

Troubleshoot application access

Troubleshooting

Learn how to troubleshoot application access problems with the Global Secure Access Windows client.

Troubleshoot prompt injection protection

Troubleshooting

Reduce risk from malicious or manipulated prompts sent to generative AI sites and apps with prompt injection protection policies in Global Secure Access.

What is Transport Layer Security Inspection?

Fundamentals

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

Windows Client Release History

General

This article tracks the changes in each released version of the Global Secure Access client for Windows.

External User Access

Fundamentals

:::image type="content" source="media/concept-external-user-access/guest-access-overview.png" alt-text="Diagram showing an overview of external user access in Global Secure Access." lightbox="media/concept-external-user-access/guest-access-overview.png":::

Connector Groups

Fundamentals

When you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.

Current Known Limitations

General

For usage in US Government community (GCC) cloud, known limitations/disclaimers include:

Operate Microsoft Traffic

Monitoring

This section is organized in the order you should implement monitoring for Microsoft traffic:

Operations

Fundamentals

- **Platform operations and monitoring engineers** who manage health checks, automation, and dashboards

Operations Common

General

- [Remote Networks operations](how-to-operate-remote-networks.md)

Explicit Forward Proxy

Fundamentals

During the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.

Explicit Forward Proxy (preview) session management

Fundamentals

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Bring Your Own Device

Fundamentals

1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).

Explicit Forward Proxy (preview) overview

Fundamentals

Explicit Forward Proxy (EFP) is one of the traffic acquisition mechanisms that's useful in scenarios where installation of the Global Secure Access (GSA) client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from:

Introduction to Proxy Automatic Configuration (PAC) files

Fundamentals

A PAC file is a mechanism used to automatically determine which proxy server a web browser or application should use for a given request. PAC files are an integral part of Explicit Forward Proxy configuration, enabling flexible and dynamic traffic steering decisions. In the context of Global Secure Access, PAC files are similar to the traffic forwarding policies of the GSA client.

PowerShell samples for Global Secure Access

General

Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, and TLS certificate creation.

Install Android Client

Fundamentals

- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).

External User Access

Fundamentals

**Q: Is this feature supported from a windows Entra registered device(BYOD)?**