GSA coexistence guide

Global Secure Access + Prisma Access

Prisma Access keeps securing internet and SaaS (SASE); GSA takes over private access and identity. They coexist via split-tunneling and selective routing.

Palo Alto Prisma Access · GlobalProtect

GSA owns

  • Private access to on-prem / legacy apps (Entra Private Access)
  • Microsoft 365 traffic
  • Identity + Conditional Access enforcement

Prisma Access owns (during coexistence)

  • Internet and SaaS traffic (SASE / GlobalProtect)
  • Private apps still served by GlobalProtect

01Choose tunnel-based or split-tunnel coexistence

Decide whether Prisma stays full-tunnel for internet while GSA handles private, or you split-tunnel so each platform sees only its traffic.

02Configure selective routing

Route private + M365 destinations to GSA; keep internet/SaaS on Prisma. Align so no destination is double-routed.

03Publish private apps through GSA

Deploy the Entra Private Network Connector and publish apps with Quick Access.

04Migrate GlobalProtect-served apps gradually

Move apps from GlobalProtect to GSA one at a time, then decommission the overlap.

When to use: you're invested in Prisma Access / GlobalProtect but want Entra-native private access and Conditional Access — consolidating toward Microsoft gradually.