Part of Global Secure Access that lets users reach private applications without a VPN, under Conditional Access control.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Entra Private Access in context, with comparison tables and the common traps.
Terms in this definition
- Global Secure Access
Brand covering Microsoft's SSE (Security Service Edge) products, namely Internet Access and Private Access from Entra, which are set up through the Microsoft Entra admin center.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Related terms
- Application segment
Destination defined on an enterprise application for Microsoft Entra Private Access, made up of an FQDN, wildcard FQDN, IP or range together with ports and protocol. Matching traffic is reachable solely by users assigned to that app.
- Global Secure Access client
Installed on iOS, Android, macOS or Windows devices, this picks up traffic with a light filter driver, not a VPN. Whatever its forwarding profiles cover is then sent on to Microsoft Entra Private Access or Internet Access.
- Private network connector
A small agent on a Windows Server inside your network that only connects outbound, on ports 80 and 443, to application proxy and Microsoft Entra Private Access. Grouping several into a connector group keeps access available.
- Quick Access
Gives VPN-style reach to whole IP ranges and FQDNs through a connector group, as a first move before you publish apps one at a time in Microsoft Entra Private Access. If a per-app Global Secure Access app overlaps it, the per-app app is used.