GSA coexistence guide
Global Secure Access + Prisma Access
Prisma Access keeps securing internet and SaaS (SASE); GSA takes over private access and identity. They coexist via split-tunneling and selective routing.
Palo Alto Prisma Access · GlobalProtect
GSA owns
- Private access to on-prem / legacy apps (Entra Private Access)
- Microsoft 365 traffic
- Identity + Conditional Access enforcement
Prisma Access owns (during coexistence)
- Internet and SaaS traffic (SASE / GlobalProtect)
- Private apps still served by GlobalProtect
01Choose tunnel-based or split-tunnel coexistence
Decide whether Prisma stays full-tunnel for internet while GSA handles private, or you split-tunnel so each platform sees only its traffic.
02Configure selective routing
Route private + M365 destinations to GSA; keep internet/SaaS on Prisma. Align so no destination is double-routed.
03Publish private apps through GSA
Deploy the Entra Private Network Connector and publish apps with Quick Access.
04Migrate GlobalProtect-served apps gradually
Move apps from GlobalProtect to GSA one at a time, then decommission the overlap.
When to use: you're invested in Prisma Access / GlobalProtect but want Entra-native private access and Conditional Access — consolidating toward Microsoft gradually.
Full configuration: Microsoft Learn — GSA + Palo Alto coexistence