We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Entra
  2. Global Secure Access
Microsoft Entra Global Secure Access for US businesses

Part of it is already in your Entra ID P1 license, including the control that stops data leaving to a personal account.

The umbrella covers two products, Internet Access and Private Access, and both are licensed through the Entra Suite. There is a third thing underneath them that is easy to miss: Internet Access aimed specifically at Microsoft services comes with P1 or P2 already, and it brings Universal Tenant Restrictions, the compliant network check and source IP restoration with it.

Book a secure access reviewSee what each license includes
Microsoft Entra Global Secure Access for US organizations
  • P1 includedInternet Access for Microsoft services
  • 190+ edgesAcross 70 regions on Microsoft network
  • No VPNPer-app access to private resources
  • 50 licensesMinimum for remote network connectivity
The distinction that changes the budget conversation

Three products, three separate licensing positions, and the odds are you already own one of them.

They are documented separately for a reason, and running them together in your head is why companies either over-buy or overlook something already sitting in their tenant.

  • The Microsoft services portion comes with P1 or P2 at no extra cost. It covers the Microsoft traffic forwarding profile, direct connectivity to Microsoft services, the compliant network check, Universal Tenant Restrictions, source IP restoration and the enriched Microsoft 365 logs. Hold P1 and all of that is available to you this afternoon.
  • The complete web gateway arrives through the Entra Suite or as a standalone purchase. This is the tier holding category and domain filtering, TLS inspection, threat intelligence, loss prevention, discovery of unsanctioned AI tools, and network security that responds to context.
  • Private Access, the zero trust network access half, comes the same way. This is the VPN replacement itself, along with Quick Access, per-application TCP and UDP reach, application discovery, private name resolution, and single sign-on spanning your internal applications.
  • One more constraint worth establishing before anybody designs branch connectivity: enabling remote network connectivity requires at least fifty licenses in total across Entra ID P1 and Entra Internet Access combined. Under that number the branch approach is simply not available, however elegant the design.
Ask which of the three you already hold
What it covers

Eight capabilities, split across three licensing positions.

Internet Access and Private Access together form the security service edge offering, with Global Secure Access as the name over the top of both. The design principles are the familiar zero trust ones, meaning grant the least you can, check every time rather than assuming, and work on the basis that somebody is already in. Delivery runs across a network reaching 70 regions and over 190 edge locations.

A slice of this is already paid for on P1, and hardly anybody realizes

The Microsoft services portion of Internet Access is included in a P1 or P2 license outright. That covers direct connectivity to Microsoft services, the compliant network check, Universal Tenant Restrictions, source IP restoration and the enriched Microsoft 365 logs. The two full products come through the Entra Suite or on their own, and both still need P1 or P2 sitting underneath for each user.

Universal Tenant Restrictions, which stops a specific leak

Universal Tenant Restrictions exist to cut the risk of data walking out into a tenant you do not control or into somebody personal account. The scenario is a member of staff signing into their own Microsoft account, or a tenant belonging to another company, on a work laptop and moving files across the gap. Almost no company has any control over that today, and this one is sitting in the P1 tier already.

Source IP restoration, which fixes your sign-in logs

Restoring the source address in sign-in logs makes threat detection more accurate. Send traffic through any network service and the original client address is normally replaced along the way, which quietly weakens every policy and risk detection that depends on where somebody is. Putting the real address back means Conditional Access and identity risk are working from where the person genuinely is rather than where the service happens to sit.

Private Access replaces a VPN rather than being one

It builds on the existing application proxy and extends the idea to any private resource, any port and any protocol. People working remotely reach private applications across hybrid and multicloud environments from whatever device and network they happen to be on, with no VPN involved, and access adapts per application according to Conditional Access rather than being granted wholesale.

Per-app access, not network access

That distinction is the entire argument. A VPN drops a machine onto the network and then trusts whatever it does there. This grants access one application at a time across TCP and UDP, with Quick Access covering a defined range of addresses or domain names, so somebody reaches the application they are entitled to instead of everything else that happens to be reachable from the same segment.

A web gateway that knows which person is behind the traffic

Internet Access sits in front of the internet and your software as a service applications as an identity-aware gateway, stopping threats, unsafe content and malicious traffic. Filtering works by category or by specific domain, with TLS inspection, threat intelligence and data loss prevention alongside. Knowing the identity is what sets it apart, because policy can then differ by person, device, location, risk and compliance state rather than by address block.

Conditional Access reaching destinations it never could before

Conditional Access policy can be applied to every internet destination, including those that have no federation relationship with Entra at all, by way of the session controls. That stretches the policy you already wrote from the applications you own out to the internet in general, which is a materially wider reach than Conditional Access has on its own.

Shadow AI discovery and prompt injection protection

The feature list now runs to discovering unsanctioned AI use and protecting against prompt injection, alongside loss prevention and network controls for agents, that last item needing a separate agent license. For companies trying to establish which AI tools their staff are genuinely using, and to control what gets pasted into them, this is a newer angle and one that matters more every quarter.

How we approach it

Four reasons this is a project to run rather than a product to buy.

Moving to a security service edge is among the bigger architectural changes a company can undertake, and it is also one where a genuine share of the benefit is sitting on licenses already bought and paid for.

We start with the part you already own

The Microsoft services portion comes with P1 or P2 and brings Universal Tenant Restrictions, the compliant network check, source IP restoration and the enriched Microsoft 365 logs. Putting that in first delivers control you did not have, proves the client and the traffic profile approach inside your own environment, and costs nothing beyond the effort of doing it.

Tenant restrictions are worth deploying for their own sake

Cutting the risk of data leaving into a tenant you do not control, or into a personal account, closes a gap nearly every company has and nearly none can currently do anything about. Somebody signing into their own Microsoft account on a work laptop is a way out that no firewall rule has ever touched, and this is the mechanism that finally does.

Private Access gets scoped application by application, not swapped in for the VPN wholesale

The whole idea is that somebody reaches the application they are entitled to and not the network that application happens to live on. Migrating a VPN by rebuilding full network access through a different product delivers precisely none of the benefit and quite a lot of the cost. Establishing what each group genuinely needs to reach is the project, and that is also where the security improvement actually comes from.

We check the constraints that stop designs late

The fifty license combined floor for remote network connectivity, which platforms will need the client installed, whether an existing service edge product is staying in place alongside this, and where TLS inspection is and is not acceptable. Every one of those has killed a design somebody asked us to review, and every one takes a few minutes to settle at the outset.

Where this matters most

Six US situations where secure service edge changes the position.

What ties these together is a workforce that stopped sitting in one building, reaching resources that stopped living in one data center, through controls that were designed for a world where both were still true.

An organization whose VPN grants far more than anybody needs

The normal state of affairs is that you connect and you are on the network, along with everything that network can see. Granting access one application at a time across TCP and UDP, with Quick Access covering named addresses or domains, means a contractor who needs one system gets one system. No amount of VPN configuration produces that outcome.

A regulated firm worried about data reaching personal accounts

Universal Tenant Restrictions cut the risk of data leaving into a tenant you do not control or into a personal account. For a firm under GLBA, under HIPAA, or holding client confidentiality obligations, somebody signing into their own Microsoft account on a company machine is a real route out and one nothing currently governs. This is a narrow control with a precise answer, and it sits in the P1 tier already.

A business with branch offices to connect

Remote network connectivity picks up traffic at the site itself rather than needing an agent on every machine, which suits locations full of shared equipment or devices nobody manages. Enabling it requires at least fifty licenses in total across Entra ID P1 and Entra Internet Access, so that is the first number to look up.

An organization whose sign-in logs show the wrong location

Once traffic runs through any network service and the original client address disappears, every location-based Conditional Access rule and every identity risk detection quietly gets worse. Restoring the source address in the sign-in logs fixes that directly, and what it improves is the accuracy of controls you are already depending on rather than adding another one to manage.

A business still maintaining a web filtering appliance

A box in a rack that only ever sees traffic originating inside the building, in a company where most people are not in the building on any given day. A cloud-delivered gateway that knows who the user is, filtering by category and domain, applies the same policy wherever somebody happens to be working, and it removes both the hardware and the backhaul that the old arrangement depended on.

An organization trying to see what AI tools staff use

Discovery of unsanctioned AI use, protection against prompt injection and loss prevention all sit inside Internet Access, with network controls for agents available under a separate agent license. In companies where AI adoption is comfortably outpacing anybody ability to write policy about it, this is one of very few places to get visibility and control at the network layer instead of finding out afterward.

Three positions

How remote and internet access is actually controlled today.

The middle column is where most American companies sit by default. A VPN handling anything private, and either a box in a rack or nothing at all handling internet traffic, with neither of them having the faintest idea who is behind the connection.
Access granted per application
Global Secure AccessYes
VPN plus an applianceNo, per network
VPN onlyNo, per network
Conditional Access applies to the connection
Global Secure AccessYes
VPN plus an applianceNo
VPN onlyNo
Policy varies by user, device, risk, and compliance
Global Secure AccessYes
VPN plus an applianceRarely
VPN onlyNo
Web filtering by category and domain
Global Secure AccessYes
VPN plus an applianceYes
VPN onlyNo
Conditional Access reaches non-federated destinations
Global Secure AccessYes
VPN plus an applianceNo
VPN onlyNo
Exfiltration to personal accounts restricted
Global Secure AccessYes
VPN plus an applianceNo
VPN onlyNo
Sign-in logs show the real client address
Global Secure AccessYes
VPN plus an applianceFrequently not
VPN onlyFrequently not
Works the same in an office and at home
Global Secure AccessYes
VPN plus an applianceNo
VPN onlyNo
Hardware to maintain
Global Secure AccessNone
VPN plus an applianceYes
VPN onlyYes
Frequency in the US mid-market
Global Secure AccessRare
VPN plus an applianceCommon
VPN onlyVery common
Feature
Global Secure Access
VPN plus an appliance
VPN only
Access granted per application
YesNo, per networkNo, per network
Conditional Access applies to the connection
YesNoNo
Policy varies by user, device, risk, and compliance
YesRarelyNo
Web filtering by category and domain
YesYesNo
Conditional Access reaches non-federated destinations
YesNoNo
Exfiltration to personal accounts restricted
YesNoNo
Sign-in logs show the real client address
YesFrequently notFrequently not
Works the same in an office and at home
YesNoNo
Hardware to maintain
NoneYesYes
Frequency in the US mid-market
RareCommonVery common
Feature by license

Reproduced from the published comparison table.

The left column is what P1 or P2 already gives you through the Microsoft traffic profile. The other two need the Entra Suite or a standalone purchase, with P1 or P2 still required underneath for each person.

Feature

Windows, macOS, iOS, and Android clients

Where it sits
All three licensing positions

Feature

Universal Continuous Access Evaluation

Where it sits
All three licensing positions

Feature

Direct Microsoft services connectivity

Where it sits
Entra ID P1 or P2, Microsoft traffic profile

Feature

Universal Tenant Restrictions

Where it sits
Entra ID P1 or P2, Microsoft traffic profile

Feature

Compliant network check

Where it sits
Entra ID P1 or P2, Microsoft traffic profile

Feature

Source IP restoration

Where it sits
Entra ID P1 or P2, Microsoft traffic profile

Feature

Microsoft 365 enriched logs

Where it sits
Entra ID P1 or P2, Microsoft traffic profile

Feature

Universal Conditional Access

Where it sits
Microsoft traffic profile and Internet Access

Feature

Remote network branch connectivity

Where it sits
Microsoft traffic profile and Internet Access, with a 50 license minimum

Feature

Web category and FQDN filtering, TLS inspection, threat intelligence

Where it sits
Internet Access license

Feature

Data loss prevention and shadow AI discovery

Where it sits
Internet Access license

Feature

VPN replacement, Quick Access, per-app TCP and UDP

Where it sits
Private Access license

Feature

Discovery of applications, private name resolution, single sign-on across internal applications

Where it sits
Private Access license
FeatureWhere it sits
Windows, macOS, iOS, and Android clientsAll three licensing positions
Universal Continuous Access EvaluationAll three licensing positions
Direct Microsoft services connectivityEntra ID P1 or P2, Microsoft traffic profile
Universal Tenant RestrictionsEntra ID P1 or P2, Microsoft traffic profile
Compliant network checkEntra ID P1 or P2, Microsoft traffic profile
Source IP restorationEntra ID P1 or P2, Microsoft traffic profile
Microsoft 365 enriched logsEntra ID P1 or P2, Microsoft traffic profile
Universal Conditional AccessMicrosoft traffic profile and Internet Access
Remote network branch connectivityMicrosoft traffic profile and Internet Access, with a 50 license minimum
Web category and FQDN filtering, TLS inspection, threat intelligenceInternet Access license
Data loss prevention and shadow AI discoveryInternet Access license
VPN replacement, Quick Access, per-app TCP and UDPPrivate Access license
Discovery of applications, private name resolution, single sign-on across internal applicationsPrivate Access license
How a deployment runs

Five steps, and if you hold P1 the first one costs nothing.

Six to twelve weeks as a rule, depending how wide it goes. The Microsoft traffic profile is a short job. Retiring a VPN properly, one application at a time, is the long piece and also the one worth doing.
  1. 1

    Establish which of the three positions you hold

    P1 or P2 covers the Microsoft services portion, while the two full products need the Entra Suite or a standalone purchase, and both still require P1 or P2 underneath for each person. That split decides what you can switch on this week and what is a buying decision.

  2. 2

    Deploy the Microsoft traffic profile first

    Because it is already included at P1 or P2 and delivers genuine controls: the compliant network check, Universal Tenant Restrictions, source IP restoration and richer logging. It also proves the client rollout and the traffic forwarding approach inside your own environment before anything larger comes to depend on either.

  3. 3

    Map what each population actually needs to reach

    This is the substance of any Private Access deployment. Which applications, on which ports and protocols, for which people, so that access is handed out per application instead of per network segment. The discovery tooling helps, and it does not remove the need to sit down with each part of the business and ask.

  4. 4

    Design the internet policy set

    Filtering by category and by domain, threat intelligence, a decision on where TLS inspection belongs and where it does not, the loss prevention rules, and Conditional Access reaching destinations that have no federation with Entra at all. Plus discovery of unsanctioned AI use wherever understanding what staff are actually running is a priority.

  5. 5

    Migrate in waves, side by side where needed

    Running this alongside an existing service edge product from another vendor is supported, which makes a phased migration realistic instead of forcing a single cutover weekend. Group by group, with the VPN switched off only once each one has per-application access to everything it genuinely needs.

Straight answers

What organizations ask about Global Secure Access.

Quite possibly. The Microsoft services portion of Internet Access is included in a P1 or P2 license outright, covering the Microsoft traffic forwarding profile, direct connectivity to Microsoft services, the compliant network check, Universal Tenant Restrictions, source IP restoration and the enriched Microsoft 365 logs. If you hold P1, all of that is available to you, and in most tenants we look at it has never once been turned on.

Both full products come inside the Entra Suite and can also be bought on their own. Either way, each person using them needs a P1 or P2 license as well. Licensing across these services is per user unless something says otherwise.

Private Access is, and the difference is not cosmetic. It builds on the existing application proxy and extends the same idea to any private resource, port and protocol, so people working remotely reach internal applications across hybrid and multicloud environments with no VPN involved, and access adapts per application under Conditional Access rather than being handed out at the network level. Per application, never per network.

A control that reduces the risk of data leaving into a tenant you do not control or into somebody personal account. In practice it deals with a member of staff signing into their own Microsoft account, or a tenant belonging to another company, on a work machine and moving files across. It sits in the P1 and P2 tier, and it closes a gap most companies currently have no answer for whatsoever.

It makes threat detection more accurate by putting the genuine client address back into the sign-in logs. Push traffic through any network service and that address is normally replaced en route, which quietly undermines every location-based Conditional Access rule and every identity risk detection you rely on. Restoring it means those controls are working from accurate information once more.

In effect yes, and it is one of the more remarkable things here. Conditional Access policy can be applied to every internet destination, including sites that have no federation relationship with your tenant, by way of the session controls. Your access policy therefore reaches a very long way past the applications anybody bothered to integrate.

The requirement is precise: at least fifty licenses in total, counting Entra ID P1 and Entra Internet Access together, before remote network connectivity can be enabled at all. Under that number the branch approach is unavailable no matter how the design is drawn, so it is worth checking the count before anybody plans site connectivity around it.

The comparison table covers clients for Windows, macOS, iOS and Android across all three licensing positions, together with traffic logging and universal Continuous Access Evaluation. Where installing a client on every machine is impractical, meaning sites full of shared or unmanaged equipment, remote network connectivity is the route instead.

Yes, and it is listed as a feature rather than a workaround. Private Access picks traffic up from the desktop client and will sit alongside whatever service edge product you already run from another vendor. That is what makes a phased migration realistic instead of forcing a hard cutover between two products over one weekend.

It guards the route out to the internet and to software as a service applications, using a gateway that knows the identity behind the traffic and stops threats, unsafe content and malicious connections. The published capability list runs to filtering by category and by specific domain, TLS inspection, threat intelligence, loss prevention, protection against prompt injection, and discovery of unsanctioned AI use.

Policy draws on real context: who the person is, what device they are on, where they are, how risky the session looks, and whether the machine meets your compliance policy, all applied through Conditional Access. A conventional gateway decides on addresses and categories. This decides on the person, the state of their hardware and the risk in front of it, which is a different class of control altogether.

Delivery runs across a network covering 70 regions and more than 190 edge locations, described as among the largest private networks anywhere. For an American deployment the question that actually matters is which points of presence serve your people and your sites, and that list is published.

On the Private Access side, both are covered. The feature list includes private name resolution and single sign-on spanning all your internal applications, alongside application discovery, Quick Access and per-application reach over TCP and UDP. Those are the pieces that make granting access one application at a time practical rather than merely better than a VPN on paper.

Internet Access and Private Access, together with Defender for Cloud Apps acting as the access broker for software as a service, are built to bring network, identity and endpoint controls into one place. The practical division of labor is that Defender for Cloud Apps governs what happens inside those applications, while this governs how people get to them in the first place.

Each engagement is scoped on its own, according to whether this is the P1 tier alone or a complete VPN retirement, how many applications have to be mapped for per-application access, and whether site connectivity is included. What costs nothing in the first conversation is working out which of the three licensing positions you already hold, because the first of them is very often paid for already.
Before deploying

Fifteen questions worth answering first.

The first block covers what is already in your hands. The second covers what is being replaced. The third covers the practical limits, and one of those rules out branch connectivity altogether below a license count.

What you already have

  • Are your users on Entra ID P1 or P2?
    The Microsoft services tier comes with it.
  • Do you hold the Entra Suite?
    That covers Internet Access and Private Access.
  • Have you enabled the Microsoft traffic profile?
    It is the part you may already own.
  • Are Universal Tenant Restrictions configured?
    They address exfiltration to personal accounts.
  • Are your sign-in logs showing real client addresses?
    Source IP restoration fixes that.

What you are replacing

  • What does your VPN actually give access to?
    Usually more than any one user needs.
  • Do you run another SSE product already?
    Side-by-side deployment is supported.
  • Is web filtering currently done on-premises?
    That appliance is what this replaces.
  • How do remote users reach private applications today?
    And what else can they reach.
  • Do you use Entra application proxy?
    Private Access builds on it.

Practical constraints

  • Do you have at least 50 combined licenses?
    Required for remote network connectivity.
  • Which platforms need the client?
    Windows, macOS, iOS, and Android are supported.
  • Are branch locations in scope?
    That is the remote network scenario.
  • Do you need TLS inspection?
    This lives inside Internet Access and brings considerations of its own.
  • Are AI tools in scope for discovery or control?
    Shadow AI discovery sits in Internet Access.
Related reading

The pages around this one.

Conditional Access

The policy layer this stretches outward, reaching even internet destinations with no federation to your tenant.

Learn more

Defender for Cloud Apps

What goes on inside those applications, sitting next to the network controls that decide how anybody gets to them.

Learn more

Entra ID P1 versus P2

How the tiers compare, including the Microsoft services capabilities that arrive with P1 at no extra cost.

Learn more
Next step

Switch on the part that comes with your P1 license.

Universal Tenant Restrictions, the compliant network check and source IP restoration all arrive with P1 or P2 through the Microsoft services tier. In most tenants not one of them has ever been switched on, which makes this the least expensive security improvement anywhere in the family.

Book a secure access reviewSee Microsoft Entra services

Related Services

Explore more solutions that work great with this service

Microsoft Entra Conditional Access Design

Conditional Access design and review for US organizations:

Learn more

Microsoft Defender for Cloud Apps

Defender for Cloud Apps deployment for US organizations: discovering

Learn more

Microsoft Entra ID P1 and P2 Licensing Review

Independent Entra ID P1 against P2 advice for US organizations:

Learn more

Continuous Access Evaluation Readiness

Continuous access evaluation readiness for US organizations: the five

Learn more

Microsoft Entra ID Protection

Entra ID Protection deployment for US organizations: establishing

Learn more

Microsoft Entra

Identity and access management solutions

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA