GSA coexistence guide

Global Secure Access + Cisco AnyConnect

Keep Cisco AnyConnect (Secure Client) for the apps you haven't migrated yet, and let GSA take over the rest with split-include routing. The classic "VPN replacement, done gradually" pattern.

Cisco AnyConnect · Secure Client / ASA remote access

GSA owns

  • Private access to published apps (Entra Private Access)
  • Microsoft 365 traffic
  • Identity + Conditional Access enforcement

Cisco AnyConnect owns (during coexistence)

  • Legacy remote access for apps not yet published to GSA
  • Non-web / TCP-UDP workloads still on the tunnel

01Inventory what still needs the VPN

Identify which apps genuinely still require the Cisco tunnel — everything else is a candidate for Entra Private Access.

02Set up split-include routing

Configure the Cisco VPN to only carry the un-migrated routes, so GSA-published apps never traverse the tunnel.

03Publish apps through GSA

Deploy the Entra Private Network Connector and publish apps with Quick Access, including TCP/UDP — no VPN needed.

04Retire the VPN when the route list empties

Shrink the split-include list as each app migrates, then decommission the Cisco VPN entirely.

When to use: you're ready to retire a Cisco ASA/AnyConnect or VPNaaS estate but need a phased cutover — migrate app by app until the tunnel is empty.