Global Secure Access (GSA)
Are you looking for information about Global Secure Access (GSA)? In this archive you will find all our posts about Global Secure Access (GSA).
-
Microsoft Entra Private Access: Secure Access for External Users to Internal Resources
Connecting external users to internal resources has traditionally been implemented using VPN. While this approach provides network connectivity, it does not consistently align with Zero Trust principles. With the external user access capability in Microsoft Entra Global Secure Access, external identities can now be integrated into existing Microsoft Entra Private Access configurations. Microsoft Entra Private Access External Users authenticate with their own identity and device and intentionally switch to the resource tenant within the Global Secure Access Client. During this tenant switch, a Private Access tunnel is established that restricts connectivity exclusively to explicitly published internal applications.
-
Microsoft Entra Private Access BYOD: Access Internal Resources with Entra Registered Devices
Until now, access to internal resources through Microsoft Entra Private Access was limited to managed devices that were either Microsoft Entra joined or Microsoft Entra hybrid joined. With the introduction of Microsoft Entra Private Access BYOD support, this limitation has been removed. Microsoft Entra registered devices can now access internal resources through Microsoft Entra Private Access, extending secure access to scenarios beyond fully managed devices.
-
Intelligent Local Access in Microsoft Entra Global Secure Access
Intelligent Local Access (ILA) addresses a core limitation of Microsoft Entra Global Secure Access: ensuring that local network traffic is handled locally. By default, Microsoft Entra Global Secure Access forwards traffic based on configured traffic forwarding profiles through the cloud-based Security Service Edge (SSE), even when the destination resides within the local network. This approach guarantees that security policies and access controls are enforced consistently at all times. As a result, local resources such as file shares or applications are routed through the cloud-based Security Service Edge (SSE), despite a direct local connection being available. The extended network path introduces additional latency and negatively impacts overall access performance.
-
Securing Microsoft 365 Apps with Microsoft Entra Global Secure Access
Strengthening secure access to Microsoft 365: Microsoft Entra Global Secure Access provides encrypted access to Microsoft 365 services such as Exchange Online and SharePoint Online through the Microsoft traffic profile. All data traffic is routed through protected network paths, ensuring reliable protection against unauthorized access.
-
Enhance Token Security with Microsoft Entra and Microsoft Intune
When an attacker steals a user’s token after a successful login, they gain the ability to impersonate the user and access protected resources without requiring a re-login. This method is becoming more commonly used to bypass security measures like Multi-Factor Authentication (MFA).