Global Secure Access + Windows 365 / Azure Virtual Desktop
Cloud PCs don't need a VPN or an Azure Network Connection to reach your on-prem apps. GSA Private Access gives Windows 365 and Azure Virtual Desktop an outbound-only path to internal resources — plus a secure path to the internet.
GSA owns
- Private access to on-prem apps via Entra Private Access connectors
- Cloud PC internet egress through GSA Internet Access (SWG)
- Identity + Conditional Access enforcement (MFA, device compliance, sign-in risk)
The legacy approach owns
- Azure Network Connection (ANC) + VPN Gateway / ExpressRoute
- Inbound network exposure to on-prem (VPN endpoints)
- Hybrid Azure AD Join line-of-sight to domain controllers
01Inventory what Cloud PCs actually need on-prem
List the file servers, LOB apps and line-of-business systems your Cloud PC users touch. Everything except domain-controller line-of-sight is a candidate for Private Access.
02Deploy Entra Private Access connectors
Install the connector group on-prem. Connectors dial out to the GSA service — no inbound firewall rules, nothing exposed to the internet.
03Publish on-prem apps to Cloud PC users
Create Private Access apps and segments for each on-prem resource and assign them to your Cloud PC user groups. Access follows identity + device posture, not network location.
04Phase out the ANC and VPN
Shrink the Azure Network Connection and VPN to only what still needs raw line-of-sight (e.g. Hybrid Join DC connectivity), then retire it as each dependency migrates.
Reference: Microsoft Learn — Global Secure Access Private Access