Product

Microsoft Entra Internet Access

Track documentation and Message Center changes for Microsoft Entra Internet Access.

Microsoft Learn documentation ↗

Latest Microsoft Entra Internet Access changes

How to manage the Internet Access profile

General

The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.

Gsa Poc Internet Access

Architecture

1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

Configure a Microsoft Entra Conditional Access policy for Explicit Forward Proxy

Authentication

Explicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.

Configure Explicit Forward Proxy

General

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

Message CenterMC1181769 on mc.merill.net ↗Stay informed
Conditional Access

Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.

Security operations for network access

Security

Security operations guide for Microsoft Entra Global Secure Access covering detection patterns and Sentinel analytics for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.

Gsa Deployment Guide Internet Access

Architecture

At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deployment. You have met [licensing requirements](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview). You're ready to enable Microsoft Entra Internet Access.

Tutorial Internet Access Introduction

Fundamentals

This series of exercises covers the fundamentals of Internet Access. The exercises assume that you follow them in order. If you skip around, you might miss a step. For example, in the baseline web-filtering tutorial, you create a security profile and assign it to a Microsoft Entra Conditional Access policy. Subsequent labs instruct you to assign the new policy to this existing security profile rather than creating a new security profile and Conditional Access policy each time.

What Is Global Secure Access

Fundamentals

| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |

How to Configure Explicit Forward Proxy (preview)

General

Explicit Forward Proxy (EFP) allows you to use Secure Web and AI Gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access (GSA) client. EFP works with any browser that supports proxy automatic configuration (PAC).

Tutorial Internet Access Application Discovery

Security

*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.

Tutorial Internet Access Enable Traffic Forwarding

Fundamentals

1. Download the GSA client for Windows 11 from one of the following links. You can also use the [sample PowerShell script](scripts/powershell-windows-client-install-proof-of-concept.md).

Tutorial: Configure content policies

Security

Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.

Configure Security

Fundamentals

| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |

How to use enriched Microsoft 365 logs

Troubleshooting

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

Zscaler Coexistence

General

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

Clients

Fundamentals

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

Traffic Forwarding

Fundamentals

With the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.

Configure Microsoft and Zscaler for a Unified SASE Solution

General

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

How to use enriched Microsoft 365 logs

Troubleshooting

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

What is Transport Layer Security Inspection?

Fundamentals

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

Netskope Coexistence

Security

Learn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.

Configure Web Content Filtering

Conditional Access

Microsoft Entra Internet Access's first Secure Web Gateway (SWG) features include web content filtering based on domain names. Microsoft integrates granular filtering policies with Microsoft Entra ID and Microsoft Entra Conditional Access, which results in filtering policies that are user-aware, context-aware, and easy to manage.

Configure Web Content Filtering

Fundamentals

Create a Conditional Access policy for end users or groups and deliver your security profile through Conditional Access Session controls. Conditional Access is the delivery mechanism for user and context awareness for Internet Access policies. To learn more about session controls, see [Conditional Access: Session](/azure/active-directory/conditional-access/concept-conditional-access-session).

userimpact: Low

Provisioning

Global Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.

Clients

Fundamentals

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

Configure Cloud Firewall

Security

Learn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.

Data Storage And Privacy

General

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

Event Enrichment Logs

Monitoring

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

Internet Access

Fundamentals

Learn about how Microsoft Entra Internet Access secures access to the Internet.

Manage Internet Access Profile

General

Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.

Points Of Presence

General

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.

Traffic Forwarding

Fundamentals

Internet access traffic can be forwarded to the service by connecting through the [Global Secure Access desktop client](how-to-install-windows-client.md).

Configure Transport Layer Security inspection settings

Security

Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access uses a two-tier Intermediate certificate model to issue dynamically generated leaf certificates for decrypting traffic. This article explains how to configure the Certificate Authority (CA) that serves as the Global Secure Access intermediate CA, including signing and uploading the certificate.

Network Content Filtering

Troubleshooting

:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::

What is Transport Layer Security inspection?

Fundamentals

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

Points Of Presence

General

The Global Secure Access service is accessed from the Global Secure Access client and is used for Microsoft Entra Internet Access (including Microsoft 365) and Microsoft Entra Private Access traffic. The Internet Protocol (IP) addresses are listed.

Cisco Vpn Coexistence

General

1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**

Netskope Coexistence

Security

This guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.

Zscaler Coexistence

Developer

In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.

Gsa Poc Private Access

Architecture

When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).

Add Intune device compliance bypasses to Global Secure Access Internet Access

Fundamentals

The [Universal Conditional Access documentation](/entra/global-secure-access/concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authorization limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertently lock users out from accessing anything on their machine.

Netskope Coexistence

General

1. **[Configuration 1: Microsoft Entra Private Access with Netskope Internet Access](#configuration-1-microsoft-entra-private-access-with-netskope-internet-access)**

Clients

Fundamentals

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

Data Storage And Privacy

General

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

Event Enrichment Logs

Monitoring

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

Internet Access

Fundamentals

Learn about how Microsoft Entra Internet Access secures access to the Internet.

Manage Internet Access Profile

General

Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.

Points Of Presence

General

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.