GSA coexistence guide
Global Secure Access + Cisco Umbrella
Umbrella keeps doing DNS-layer security (and SWG if you use it); GSA takes over private access and identity. A clean split, since they operate at different layers of the stack.
Cisco Umbrella
GSA owns
- Private access to on-prem / legacy apps (Entra Private Access)
- Microsoft 365 traffic
- Identity + Conditional Access enforcement
Cisco Umbrella owns (during coexistence)
- DNS-layer security (first-hop resolution and filtering)
- Secure Web Gateway, where in use
01Keep Umbrella as your DNS layer
Umbrella continues resolving and filtering DNS at the first hop — GSA doesn't need to take that over for coexistence to work.
02Steer internet via Umbrella, private via GSA
Route internet/SaaS traffic through Umbrella's SWG while GSA handles private apps and M365 — the two don't overlap.
03Publish private apps through GSA
Deploy the Entra Private Network Connector and publish your on-prem apps with Quick Access, alongside Umbrella's internet path.
When to use: you rely on Umbrella for DNS/SWG but want Entra-native private access — a natural fit, since the two platforms sit at different layers.
Full configuration: Microsoft Learn — GSA + Cisco Umbrella coexistence