Gsa Deployment Guide Private Access
1. Create end user communications to set expectations and provide an escalation path.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra Private Access.
Microsoft Learn documentation ↗1. Create end user communications to set expectations and provide an escalation path.
Zscaler Private Access (ZPA) is available in the following [national cloud deployments](/graph/deployments).
Zscaler Private Access (ZPA) is available in the following [national cloud deployments](/graph/deployments).
Zscaler Private Access Administrator is available in the following [national cloud deployments](/graph/deployments).
This article tracks the released versions of the Microsoft Entra Private Access Sensor and the changes in each version.
Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
Learn how to monitor and troubleshoot private application access scenarios that require the Microsoft Entra Private Access connector, using Microsoft Entra Health monitoring tools.
Learn how to migrate client devices from DirectAccess to Microsoft Entra Private Access with a phased approach that avoids tunnel conflicts and connectivity failures.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn best practices for transitioning from VPN replacement with Quick Access to per-application segmentation using Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.
| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |
Guest users are only billed when they actively sign in to the Global Secure Access client for Private Access.
Post-deployment operations guide for Microsoft Entra Private Access, the Zero Trust network access (ZTNA) capability, covering alerting, health checks, integration, automation, and operational metrics.
Intelligent Local Access capability can help optimize the traffic flow from Microsoft Entra clients to Microsoft Entra Private Access apps when the client is on a corporate/private network. This article explains how to enable the Intelligent Private Network for Microsoft Entra Private Access.
Learn how to migrate client devices from DirectAccess to Microsoft Entra Private Access with a phased approach that avoids tunnel conflicts and connectivity failures.
DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.
Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Set up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
After a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.
Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
Set up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
Learn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.
Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
How to apply Conditional Access policies to Microsoft Entra Private Access apps.
Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Learn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how Microsoft Entra private network connector groups work, and how Microsoft Entra Private Access and application proxy use them.
Learn how Microsoft Entra private network connectors work and how Microsoft Entra Private Access and application proxy use them.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.
Covers how to provide single sign-on using Kerberos with Microsoft Entra Private Access.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
- Use **Event Viewer** from **Application and Service Logs** > **Microsoft** > **Windows** > **Private Access Sensor** to review Private Access Sensor logs.
Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
To configure Microsoft Entra Private Access for Active Directory Domain Controllers, you must have the following:
5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.
manager: dougeby
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Configuring your Quick Access settings is a major component to utilizing Microsoft Entra Private Access. When you configure Quick Access for the first time, Private Access creates a new enterprise application. The properties of this new app are automatically configured to work with Private Access.
Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how Microsoft Entra private network connector groups work and how they're used by Microsoft Entra Private Access and application proxy.
Learn how Microsoft Entra private network connectors work and how they're used by Microsoft Entra Private Access and application proxy.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Covers how to provide single sign-on using Kerberos with Microsoft Entra Private Access.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
ai-usage: ai-assisted
- The connector now supports routing outbound traffic to destinations in Microsoft Entra Private Access through a forward proxy, enhancing network control.
The scenario outlined in this article assumes that you already have the following prerequisites:
The scenario outlined in this article assumes that you already have the following prerequisites:
- The connector now supports routing outbound traffic to destination in GSA Private Access through a forward proxy, enhancing network control.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
For the scenario where you need to control access to specific *critical* resources, such as highly valued servers and applications, Microsoft recommends that you add an extra security layer by enforcing just-in-time privileged access on top of their already secured private access.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Conditional Access policies for Private Access are configured at the application level for each app. Conditional Access policies can be created and applied to the application from two places:
**To add Zscaler Private Access (ZPA) from the Microsoft Entra application gallery, perform the following steps:**
To configure the integration of Zscaler Private Access (ZPA) into Microsoft Entra ID, you need to add Zscaler Private Access (ZPA) from the gallery to your list of managed SaaS apps.
To configure the integration of Zscaler Private Access Administrator into Microsoft Entra ID, you need to add Zscaler Private Access Administrator from the gallery to your list of managed SaaS apps.
Learn how Microsoft Entra private network connector groups work and how they're used by Microsoft Entra Private Access and application proxy.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
- [Microsoft Global Secure Access Deployment Guide for Microsoft Entra Private Access](gsa-deployment-guide-private-access.md)
ai-usage: ai-assisted
ai-usage: ai-assisted