Explainer

What is Global Secure Access?

Global Secure Access (GSA) is Microsoft's Secure Service Edge platform — the umbrella term for Entra Internet Access and Entra Private Access, plus the Microsoft traffic profile. It moves identity to the centre of network access, so Entra ID customers can enforce Zero Trust policy on every connection.

01The three traffic-forwarding profiles

In the Entra admin center, GSA lives under Global Secure Access → Connect → Traffic forwarding, which contains three profiles:

  • Microsoft traffic profile — steers Microsoft 365 and Entra traffic through the GSA edge. Included with Entra ID P1/P2.
  • Private Access profile — per-app, identity-based access to on-premises and private apps (the VPN replacement).
  • Internet Access profile — secure web gateway / firewall-as-a-service for internet and SaaS traffic.

02How traffic gets there

End-user devices run the Global Secure Access client, which forwards matching traffic to the nearest Microsoft edge. Branch offices can instead use a remote network (IPSec/GRE tunnel from a supported device). Policy is then applied through Conditional Access — so identity, device posture and risk decide what each user can reach, not the network they happen to be on.

03Why it matters for Entra ID customers

If you already run Entra ID, GSA extends the identity plane you trust to the network layer. Instead of a separate VPN or SWG with its own policy engine, access decisions live in one place: Conditional Access. That means fewer consoles, one enforcement model, and a consistent Zero Trust story across M365, private apps and the internet.

04How it fits with your existing vendors

Adopting GSA rarely means ripping out Zscaler, Netskope or Cisco overnight. GSA is designed to coexist — you split traffic so each platform owns what it's best at, and migrate app by app. This is the pattern we see most often in practice.

The lowest-risk first step is enabling the Microsoft traffic profile — it's included with Entra ID P1/P2 and steers only M365 traffic, so it doesn't touch your existing VPN or internet security stack.