GSA coexistence guide

Global Secure Access + Netskope

Netskope keeps securing internet and SaaS (CASB/SWG); GSA takes over private access and identity. Coexistence hinges on steering configuration and network location profiles.

Netskope

GSA owns

  • Private access to on-prem / legacy apps (Entra Private Access)
  • Microsoft 365 traffic
  • Identity + Conditional Access enforcement

Netskope owns (during coexistence)

  • Internet and SaaS traffic (CASB / SWG)
  • Netskope ZTNA for apps you're not yet moving

01Configure steering

Set steering so private + M365 traffic goes to GSA while internet/SaaS continues through Netskope — no destination double-routed.

02Align network location profiles

Make sure Netskope's network location awareness and GSA's forwarding profiles agree on what "on-premises" vs "remote" means.

03Publish private apps through GSA

Deploy the Entra Private Network Connector and publish apps with Quick Access.

04Migrate Netskope ZTNA apps gradually

Move apps from Netskope ZTNA to GSA app by app, then retire the overlap.

When to use: you're on Netskope for internet/SaaS security and want Entra-native private access with Conditional Access — consolidating toward Microsoft gradually.