GSA coexistence guide
Global Secure Access + Cisco AnyConnect
Keep Cisco AnyConnect (Secure Client) for the apps you haven't migrated yet, and let GSA take over the rest with split-include routing. The classic "VPN replacement, done gradually" pattern.
Cisco AnyConnect · Secure Client / ASA remote access
GSA owns
- Private access to published apps (Entra Private Access)
- Microsoft 365 traffic
- Identity + Conditional Access enforcement
Cisco AnyConnect owns (during coexistence)
- Legacy remote access for apps not yet published to GSA
- Non-web / TCP-UDP workloads still on the tunnel
01Inventory what still needs the VPN
Identify which apps genuinely still require the Cisco tunnel — everything else is a candidate for Entra Private Access.
02Set up split-include routing
Configure the Cisco VPN to only carry the un-migrated routes, so GSA-published apps never traverse the tunnel.
03Publish apps through GSA
Deploy the Entra Private Network Connector and publish apps with Quick Access, including TCP/UDP — no VPN needed.
04Retire the VPN when the route list empties
Shrink the split-include list as each app migrates, then decommission the Cisco VPN entirely.
When to use: you're ready to retire a Cisco ASA/AnyConnect or VPNaaS estate but need a phased cutover — migrate app by app until the tunnel is empty.
Full configuration: Microsoft Learn — GSA + Cisco VPN coexistence