GSA coexistence guide

Global Secure Access + Cisco Umbrella

Umbrella keeps doing DNS-layer security (and SWG if you use it); GSA takes over private access and identity. A clean split, since they operate at different layers of the stack.

Cisco Umbrella

GSA owns

  • Private access to on-prem / legacy apps (Entra Private Access)
  • Microsoft 365 traffic
  • Identity + Conditional Access enforcement

Cisco Umbrella owns (during coexistence)

  • DNS-layer security (first-hop resolution and filtering)
  • Secure Web Gateway, where in use

01Keep Umbrella as your DNS layer

Umbrella continues resolving and filtering DNS at the first hop — GSA doesn't need to take that over for coexistence to work.

02Steer internet via Umbrella, private via GSA

Route internet/SaaS traffic through Umbrella's SWG while GSA handles private apps and M365 — the two don't overlap.

03Publish private apps through GSA

Deploy the Entra Private Network Connector and publish your on-prem apps with Quick Access, alongside Umbrella's internet path.

When to use: you rely on Umbrella for DNS/SWG but want Entra-native private access — a natural fit, since the two platforms sit at different layers.