A secure web gateway within Global Secure Access that knows who the user is. Security profiles tied to Conditional Access decide which websites and SaaS services are allowed, judged by FQDN or category, and ports beyond the default 80 and 443 can be captured with custom rules.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Entra Internet Access in context, with comparison tables and the common traps.
Terms in this definition
- Secure Web Gateway
Filters web and SaaS traffic by policy. Defender for Cloud Apps can plug into third-party products of this type to stop unsanctioned apps, and Microsoft's own, identity-aware one is Microsoft Entra Internet Access.
- Global Secure Access
Brand covering Microsoft's SSE (Security Service Edge) products, namely Internet Access and Private Access from Entra, which are set up through the Microsoft Entra admin center.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- SaaS
A cloud model in which you consume a finished application that the provider operates, Microsoft 365 for instance. Nearly everything is the provider's job; you look after your data, users and devices.
- FQDN
The full DNS name of a host, zone included, for example www.contoso.com.
Related terms
- NetworkAccessTraffic
Table in Log Analytics recording traffic events from Global Secure Access, that is Microsoft Entra Internet Access and Private Access. Azure VNet flow data is not stored in it.
- QUIC
Browsers often try this UDP-based protocol on port 443 first, but Microsoft Entra Internet Access can't tunnel it. Switching it off in the browser forces a fallback to ordinary HTTPS over TCP.