Part of it is already in your Entra ID P1 license, including the control that stops data leaving to a personal account.
The umbrella covers two products, Internet Access and Private Access, and both are licensed through the Entra Suite. There is a third thing underneath them that is easy to miss: Internet Access aimed specifically at Microsoft services comes with P1 or P2 already, and it brings Universal Tenant Restrictions, the compliant network check and source IP restoration with it.

- P1 includedInternet Access for Microsoft services
- 190+ edgesAcross 70 regions on Microsoft network
- No VPNPer-app access to private resources
- 50 licensesMinimum for remote network connectivity
Three products, three separate licensing positions, and the odds are you already own one of them.
They are documented separately for a reason, and running them together in your head is why companies either over-buy or overlook something already sitting in their tenant.
- The Microsoft services portion comes with P1 or P2 at no extra cost. It covers the Microsoft traffic forwarding profile, direct connectivity to Microsoft services, the compliant network check, Universal Tenant Restrictions, source IP restoration and the enriched Microsoft 365 logs. Hold P1 and all of that is available to you this afternoon.
- The complete web gateway arrives through the Entra Suite or as a standalone purchase. This is the tier holding category and domain filtering, TLS inspection, threat intelligence, loss prevention, discovery of unsanctioned AI tools, and network security that responds to context.
- Private Access, the zero trust network access half, comes the same way. This is the VPN replacement itself, along with Quick Access, per-application TCP and UDP reach, application discovery, private name resolution, and single sign-on spanning your internal applications.
- One more constraint worth establishing before anybody designs branch connectivity: enabling remote network connectivity requires at least fifty licenses in total across Entra ID P1 and Entra Internet Access combined. Under that number the branch approach is simply not available, however elegant the design.
Eight capabilities, split across three licensing positions.
A slice of this is already paid for on P1, and hardly anybody realizes
The Microsoft services portion of Internet Access is included in a P1 or P2 license outright. That covers direct connectivity to Microsoft services, the compliant network check, Universal Tenant Restrictions, source IP restoration and the enriched Microsoft 365 logs. The two full products come through the Entra Suite or on their own, and both still need P1 or P2 sitting underneath for each user.
Universal Tenant Restrictions, which stops a specific leak
Universal Tenant Restrictions exist to cut the risk of data walking out into a tenant you do not control or into somebody personal account. The scenario is a member of staff signing into their own Microsoft account, or a tenant belonging to another company, on a work laptop and moving files across the gap. Almost no company has any control over that today, and this one is sitting in the P1 tier already.
Source IP restoration, which fixes your sign-in logs
Restoring the source address in sign-in logs makes threat detection more accurate. Send traffic through any network service and the original client address is normally replaced along the way, which quietly weakens every policy and risk detection that depends on where somebody is. Putting the real address back means Conditional Access and identity risk are working from where the person genuinely is rather than where the service happens to sit.
Private Access replaces a VPN rather than being one
It builds on the existing application proxy and extends the idea to any private resource, any port and any protocol. People working remotely reach private applications across hybrid and multicloud environments from whatever device and network they happen to be on, with no VPN involved, and access adapts per application according to Conditional Access rather than being granted wholesale.
Per-app access, not network access
That distinction is the entire argument. A VPN drops a machine onto the network and then trusts whatever it does there. This grants access one application at a time across TCP and UDP, with Quick Access covering a defined range of addresses or domain names, so somebody reaches the application they are entitled to instead of everything else that happens to be reachable from the same segment.
A web gateway that knows which person is behind the traffic
Internet Access sits in front of the internet and your software as a service applications as an identity-aware gateway, stopping threats, unsafe content and malicious traffic. Filtering works by category or by specific domain, with TLS inspection, threat intelligence and data loss prevention alongside. Knowing the identity is what sets it apart, because policy can then differ by person, device, location, risk and compliance state rather than by address block.
Conditional Access reaching destinations it never could before
Conditional Access policy can be applied to every internet destination, including those that have no federation relationship with Entra at all, by way of the session controls. That stretches the policy you already wrote from the applications you own out to the internet in general, which is a materially wider reach than Conditional Access has on its own.
Shadow AI discovery and prompt injection protection
The feature list now runs to discovering unsanctioned AI use and protecting against prompt injection, alongside loss prevention and network controls for agents, that last item needing a separate agent license. For companies trying to establish which AI tools their staff are genuinely using, and to control what gets pasted into them, this is a newer angle and one that matters more every quarter.
Four reasons this is a project to run rather than a product to buy.
We start with the part you already own
The Microsoft services portion comes with P1 or P2 and brings Universal Tenant Restrictions, the compliant network check, source IP restoration and the enriched Microsoft 365 logs. Putting that in first delivers control you did not have, proves the client and the traffic profile approach inside your own environment, and costs nothing beyond the effort of doing it.
Tenant restrictions are worth deploying for their own sake
Cutting the risk of data leaving into a tenant you do not control, or into a personal account, closes a gap nearly every company has and nearly none can currently do anything about. Somebody signing into their own Microsoft account on a work laptop is a way out that no firewall rule has ever touched, and this is the mechanism that finally does.
Private Access gets scoped application by application, not swapped in for the VPN wholesale
The whole idea is that somebody reaches the application they are entitled to and not the network that application happens to live on. Migrating a VPN by rebuilding full network access through a different product delivers precisely none of the benefit and quite a lot of the cost. Establishing what each group genuinely needs to reach is the project, and that is also where the security improvement actually comes from.
We check the constraints that stop designs late
The fifty license combined floor for remote network connectivity, which platforms will need the client installed, whether an existing service edge product is staying in place alongside this, and where TLS inspection is and is not acceptable. Every one of those has killed a design somebody asked us to review, and every one takes a few minutes to settle at the outset.
Six US situations where secure service edge changes the position.
An organization whose VPN grants far more than anybody needs
The normal state of affairs is that you connect and you are on the network, along with everything that network can see. Granting access one application at a time across TCP and UDP, with Quick Access covering named addresses or domains, means a contractor who needs one system gets one system. No amount of VPN configuration produces that outcome.
A regulated firm worried about data reaching personal accounts
Universal Tenant Restrictions cut the risk of data leaving into a tenant you do not control or into a personal account. For a firm under GLBA, under HIPAA, or holding client confidentiality obligations, somebody signing into their own Microsoft account on a company machine is a real route out and one nothing currently governs. This is a narrow control with a precise answer, and it sits in the P1 tier already.
A business with branch offices to connect
Remote network connectivity picks up traffic at the site itself rather than needing an agent on every machine, which suits locations full of shared equipment or devices nobody manages. Enabling it requires at least fifty licenses in total across Entra ID P1 and Entra Internet Access, so that is the first number to look up.
An organization whose sign-in logs show the wrong location
Once traffic runs through any network service and the original client address disappears, every location-based Conditional Access rule and every identity risk detection quietly gets worse. Restoring the source address in the sign-in logs fixes that directly, and what it improves is the accuracy of controls you are already depending on rather than adding another one to manage.
A business still maintaining a web filtering appliance
A box in a rack that only ever sees traffic originating inside the building, in a company where most people are not in the building on any given day. A cloud-delivered gateway that knows who the user is, filtering by category and domain, applies the same policy wherever somebody happens to be working, and it removes both the hardware and the backhaul that the old arrangement depended on.
An organization trying to see what AI tools staff use
Discovery of unsanctioned AI use, protection against prompt injection and loss prevention all sit inside Internet Access, with network controls for agents available under a separate agent license. In companies where AI adoption is comfortably outpacing anybody ability to write policy about it, this is one of very few places to get visibility and control at the network layer instead of finding out afterward.
How remote and internet access is actually controlled today.
| Feature | Global Secure Access | VPN plus an appliance | VPN only |
|---|---|---|---|
Access granted per application | Yes | No, per network | No, per network |
Conditional Access applies to the connection | Yes | No | No |
Policy varies by user, device, risk, and compliance | Yes | Rarely | No |
Web filtering by category and domain | Yes | Yes | No |
Conditional Access reaches non-federated destinations | Yes | No | No |
Exfiltration to personal accounts restricted | Yes | No | No |
Sign-in logs show the real client address | Yes | Frequently not | Frequently not |
Works the same in an office and at home | Yes | No | No |
Hardware to maintain | None | Yes | Yes |
Frequency in the US mid-market | Rare | Common | Very common |
Reproduced from the published comparison table.
Feature
Windows, macOS, iOS, and Android clients
- Where it sits
- All three licensing positions
Feature
Universal Continuous Access Evaluation
- Where it sits
- All three licensing positions
Feature
Direct Microsoft services connectivity
- Where it sits
- Entra ID P1 or P2, Microsoft traffic profile
Feature
Universal Tenant Restrictions
- Where it sits
- Entra ID P1 or P2, Microsoft traffic profile
Feature
Compliant network check
- Where it sits
- Entra ID P1 or P2, Microsoft traffic profile
Feature
Source IP restoration
- Where it sits
- Entra ID P1 or P2, Microsoft traffic profile
Feature
Microsoft 365 enriched logs
- Where it sits
- Entra ID P1 or P2, Microsoft traffic profile
Feature
Universal Conditional Access
- Where it sits
- Microsoft traffic profile and Internet Access
Feature
Remote network branch connectivity
- Where it sits
- Microsoft traffic profile and Internet Access, with a 50 license minimum
Feature
Web category and FQDN filtering, TLS inspection, threat intelligence
- Where it sits
- Internet Access license
Feature
Data loss prevention and shadow AI discovery
- Where it sits
- Internet Access license
Feature
VPN replacement, Quick Access, per-app TCP and UDP
- Where it sits
- Private Access license
Feature
Discovery of applications, private name resolution, single sign-on across internal applications
- Where it sits
- Private Access license
Five steps, and if you hold P1 the first one costs nothing.
- 1
Establish which of the three positions you hold
P1 or P2 covers the Microsoft services portion, while the two full products need the Entra Suite or a standalone purchase, and both still require P1 or P2 underneath for each person. That split decides what you can switch on this week and what is a buying decision.
- 2
Deploy the Microsoft traffic profile first
Because it is already included at P1 or P2 and delivers genuine controls: the compliant network check, Universal Tenant Restrictions, source IP restoration and richer logging. It also proves the client rollout and the traffic forwarding approach inside your own environment before anything larger comes to depend on either.
- 3
Map what each population actually needs to reach
This is the substance of any Private Access deployment. Which applications, on which ports and protocols, for which people, so that access is handed out per application instead of per network segment. The discovery tooling helps, and it does not remove the need to sit down with each part of the business and ask.
- 4
Design the internet policy set
Filtering by category and by domain, threat intelligence, a decision on where TLS inspection belongs and where it does not, the loss prevention rules, and Conditional Access reaching destinations that have no federation with Entra at all. Plus discovery of unsanctioned AI use wherever understanding what staff are actually running is a priority.
- 5
Migrate in waves, side by side where needed
Running this alongside an existing service edge product from another vendor is supported, which makes a phased migration realistic instead of forcing a single cutover weekend. Group by group, with the VPN switched off only once each one has per-application access to everything it genuinely needs.
What organizations ask about Global Secure Access.
Fifteen questions worth answering first.
What you already have
- Are your users on Entra ID P1 or P2?The Microsoft services tier comes with it.
- Do you hold the Entra Suite?That covers Internet Access and Private Access.
- Have you enabled the Microsoft traffic profile?It is the part you may already own.
- Are Universal Tenant Restrictions configured?They address exfiltration to personal accounts.
- Are your sign-in logs showing real client addresses?Source IP restoration fixes that.
What you are replacing
- What does your VPN actually give access to?Usually more than any one user needs.
- Do you run another SSE product already?Side-by-side deployment is supported.
- Is web filtering currently done on-premises?That appliance is what this replaces.
- How do remote users reach private applications today?And what else can they reach.
- Do you use Entra application proxy?Private Access builds on it.
Practical constraints
- Do you have at least 50 combined licenses?Required for remote network connectivity.
- Which platforms need the client?Windows, macOS, iOS, and Android are supported.
- Are branch locations in scope?That is the remote network scenario.
- Do you need TLS inspection?This lives inside Internet Access and brings considerations of its own.
- Are AI tools in scope for discovery or control?Shadow AI discovery sits in Internet Access.
The pages around this one.
Conditional Access
The policy layer this stretches outward, reaching even internet destinations with no federation to your tenant.
Defender for Cloud Apps
What goes on inside those applications, sitting next to the network controls that decide how anybody gets to them.
Entra ID P1 versus P2
How the tiers compare, including the Microsoft services capabilities that arrive with P1 at no extra cost.
Switch on the part that comes with your P1 license.
Universal Tenant Restrictions, the compliant network check and source IP restoration all arrive with P1 or P2 through the Microsoft services tier. In most tenants not one of them has ever been switched on, which makes this the least expensive security improvement anywhere in the family.
Related Services
Explore more solutions that work great with this service
Microsoft Entra Conditional Access Design
Conditional Access design and review for US organizations:
Learn moreMicrosoft Defender for Cloud Apps
Defender for Cloud Apps deployment for US organizations: discovering
Learn moreMicrosoft Entra ID P1 and P2 Licensing Review
Independent Entra ID P1 against P2 advice for US organizations:
Learn moreContinuous Access Evaluation Readiness
Continuous access evaluation readiness for US organizations: the five
Learn moreMicrosoft Entra ID Protection
Entra ID Protection deployment for US organizations: establishing
Learn moreMicrosoft Entra
Identity and access management solutions
Learn more