GSA coexistence guide

Global Secure Access + Cisco Secure Access

Cisco Secure Access (formerly Cisco+ Secure Connect) brings Secure Internet Access and Zero Trust Access; GSA brings Entra-native private access. They coexist by splitting internet vs private workloads.

Cisco Secure Access

GSA owns

  • Private access to on-prem / legacy apps (Entra Private Access)
  • Microsoft 365 traffic
  • Identity + Conditional Access enforcement

Cisco Secure Access owns (during coexistence)

  • Secure Internet Access (SWG / DNS security)
  • Zero Trust Access for apps you're not yet moving

01Split internet vs private

Keep Secure Internet Access for internet/SaaS; point private app access at Entra Private Access. Decide the boundary explicitly.

02Align steering rules

Make sure Cisco Secure Access steering and GSA forwarding profiles don't fight over the same traffic.

03Publish private apps through GSA

Deploy the Entra Private Network Connector and publish apps with Quick Access.

04Migrate Zero Trust Access apps gradually

Move ZTA-published apps to GSA app by app, then retire the overlap when it's empty.

When to use: you're on Cisco Secure Access for internet security and want Entra-native private access, consolidating toward Microsoft without a big-bang migration.