GSA integration guide

Global Secure Access + Windows 365 / Azure Virtual Desktop

Cloud PCs don't need a VPN or an Azure Network Connection to reach your on-prem apps. GSA Private Access gives Windows 365 and Azure Virtual Desktop an outbound-only path to internal resources — plus a secure path to the internet.

Windows 365 · Azure Virtual Desktop · Microsoft

GSA owns

  • Private access to on-prem apps via Entra Private Access connectors
  • Cloud PC internet egress through GSA Internet Access (SWG)
  • Identity + Conditional Access enforcement (MFA, device compliance, sign-in risk)

The legacy approach owns

  • Azure Network Connection (ANC) + VPN Gateway / ExpressRoute
  • Inbound network exposure to on-prem (VPN endpoints)
  • Hybrid Azure AD Join line-of-sight to domain controllers
Before — legacy path
Cloud PC Azure Network Connection vNet + VPN Gateway / ExpressRoute On-prem apps inbound exposure · line-of-sight required
After — GSA Private Access
Cloud PC Entra GSA Private Access connectors · outbound-only On-prem apps outbound-only · nothing listening

01Inventory what Cloud PCs actually need on-prem

List the file servers, LOB apps and line-of-business systems your Cloud PC users touch. Everything except domain-controller line-of-sight is a candidate for Private Access.

02Deploy Entra Private Access connectors

Install the connector group on-prem. Connectors dial out to the GSA service — no inbound firewall rules, nothing exposed to the internet.

03Publish on-prem apps to Cloud PC users

Create Private Access apps and segments for each on-prem resource and assign them to your Cloud PC user groups. Access follows identity + device posture, not network location.

04Phase out the ANC and VPN

Shrink the Azure Network Connection and VPN to only what still needs raw line-of-sight (e.g. Hybrid Join DC connectivity), then retire it as each dependency migrates.

When to use: you're provisioning Windows 365 Enterprise or Azure Virtual Desktop and want Cloud PCs to reach on-prem apps without standing up an Azure Network Connection, VPN Gateway or ExpressRoute — or you're replacing an existing VDI VPN with GSA.