Brand covering Microsoft's SSE (Security Service Edge) products, namely Internet Access and Private Access from Entra, which are set up through the Microsoft Entra admin center.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Global Secure Access in context, with comparison tables and the common traps.
Terms in this definition
- Security Service Edge
Delivers network security from the cloud with identity at its centre; Microsoft's offering, Global Secure Access, combines Internet Access with Private Access. Here SSE has nothing to do with server-side encryption.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Microsoft Entra admin center
The portal, at entra.microsoft.com, where admins look after identity in Microsoft Entra: users and groups, role assignments, Conditional Access, app registrations, sign-in methods and identity logs.
Related terms
- Application discovery
Lists which Quick Access segments people have actually used over the previous 30 days, so administrators can replace broad Quick Access with separate, per-app Private Access entries. Found among the Global Secure Access reports.
- Baseline profile
Applies to every bit of Internet Access traffic, remote networks included, without needing a Conditional Access policy, and it still runs even if another profile matches first. This Global Secure Access security profile has priority 65000, the lowest available.
- Compliant network check
Means sign-ins must come through your tenant's Global Secure Access, whether from the client or a remote network, so you no longer maintain egress IP lists. In Conditional Access it shows up as the named location All Compliant Network locations.
- Global Secure Access Administrator
Can look after remote networks, traffic logs, security profiles and traffic forwarding profiles in Global Secure Access. Setting up Private Access apps and Conditional Access policies is outside what this Microsoft Entra role allows.
- Microsoft Entra Internet Access
A secure web gateway within Global Secure Access that knows who the user is. Security profiles tied to Conditional Access decide which websites and SaaS services are allowed, judged by FQDN or category, and ports beyond the default 80 and 443 can be captured with custom rules.
- Microsoft Entra Private Access
Part of Global Secure Access that lets users reach private applications without a VPN, under Conditional Access control.
- Microsoft traffic profile
Forwards Teams, Exchange Online, SharePoint Online, OneDrive and Microsoft 365 Common traffic through Global Secure Access, which lets you use universal tenant restrictions and compliant network checks.
- NetworkAccessTraffic
Table in Log Analytics recording traffic events from Global Secure Access, that is Microsoft Entra Internet Access and Private Access. Azure VNet flow data is not stored in it.