GSA coexistence guide
Global Secure Access + Netskope
Netskope keeps securing internet and SaaS (CASB/SWG); GSA takes over private access and identity. Coexistence hinges on steering configuration and network location profiles.
Netskope
GSA owns
- Private access to on-prem / legacy apps (Entra Private Access)
- Microsoft 365 traffic
- Identity + Conditional Access enforcement
Netskope owns (during coexistence)
- Internet and SaaS traffic (CASB / SWG)
- Netskope ZTNA for apps you're not yet moving
01Configure steering
Set steering so private + M365 traffic goes to GSA while internet/SaaS continues through Netskope — no destination double-routed.
02Align network location profiles
Make sure Netskope's network location awareness and GSA's forwarding profiles agree on what "on-premises" vs "remote" means.
03Publish private apps through GSA
Deploy the Entra Private Network Connector and publish apps with Quick Access.
04Migrate Netskope ZTNA apps gradually
Move apps from Netskope ZTNA to GSA app by app, then retire the overlap.
When to use: you're on Netskope for internet/SaaS security and want Entra-native private access with Conditional Access — consolidating toward Microsoft gradually.
Full configuration: Microsoft Learn — GSA + Netskope coexistence