Microsoft Entra Internet Access

Microsoft Entra Internet Access

A couple of weeks ago I posted about what Microsoft Entra Internet and Private access are here

In todays post, we're going to discuss how you can secure access to your company's resources using the Microsoft Entra Internet Access Client, also known as Global Secure Access. This tool primarily serves to segregate traffic for Microsoft 365 applications and resources, such as Exchange Online and SharePoint Online

Users can gain access to these resources via the Global Secure Access Client or from a remote network like a branch office, but for this post, we're only discussing the use of the client.


Initial Setup

First, visit https://entra.microsoft.com/ and then:

  1. Enable the Global Secure Access

No alt text provided for this image


Creating a traffic forwarding profile

  1. Navigate to Global Secure Access > Connect > Traffic forwarding.
  2. Tick the checkbox for the Microsoft 365 access profile.

No alt text provided for this image


Creating the Conditional Access policy

Next, we need to establish a conditional access policy that routes traffic through Global Secure Access. In my setup, all user access is denied by default unless the client is installed, so without the client, users are unable to access company resources.

To implement this:

  1. Create the Conditional Access Policy

No alt text provided for this image
No alt text provided for this image
No alt text provided for this image
No alt text provided for this image


Installing the Global Secure Access Client

  1. Install and configure the Global Secure Access Client on end-user devices.
  2. Log into the Microsoft Entra admin center as a Global Secure Access Administrator.
  3. Proceed to Global Secure Access (Preview) > Devices > Clients.

No alt text provided for this image

4. Launch the installer from the machine you want to access M365 from

No alt text provided for this image
No alt text provided for this image
No alt text provided for this image

5. Once the install is finished you'll be prompted to login as your authorized user

No alt text provided for this image

6. Confimed Global Secure Access is connected

No alt text provided for this image


Testing

Finally, let's run some tests..

Testing Sharepoint from a device without the client installed...

No alt text provided for this image


And now, testing from a device with the client installed...


No alt text provided for this image

As you can see it was very easy to setup. I wont delve into universal tenant restrictions or enhanced signalling but you can view more about that here

In my next post I'll talk about securing access to internal applications without a VPN using Entra Private Access.. Stay tuned for more

Toa Greening

Information Technology Security Architect, microCAR EVangelist, Radio Spectrum Kaitiaki, Experienced Director and Trustee

1 年

Very good, multi tenant?

回复

要查看或添加评论,请登录

?? Luke McAlpine的更多文章

社区洞察

其他会员也浏览了