Microsoft Entra Private Access
Troubleshooting

How to investigate private application access requiring Microsoft Entra Private Access connector

In brief

The documentation now requires a non-trial Microsoft Entra P1 or P2 license plus at least 100 monthly active users to view alerts and receive notifications. It also clarifies Private Access licensing, least-privilege roles, Graph permissions, and expanded signal and alert investigation guidance.

What Entra admins need to know

Administrators should verify licensing and access assignments before configuring or investigating Private Access health alerts.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

This article describes the health metrics related to private application access requiring Microsoft Entra Private Access connector and how to troubleshoot a potential issue when you receive an alert.

Prerequisites

There are different roles, permissions, and license requirements to view health monitoring signals and configure and receive alerts. We recommend using a role with least privilege access to align with the Zero Trust guidance.

  • A tenant with a Microsoft Entra P1 or P2 license is required to view the Microsoft Entra health scenario monitoring signals.

  • A tenant with both a non-trial Microsoft Entra P1 or P2 license and at least 100 monthly active users is required to view alerts and receive alert notifications.

  • A tenant with a Microsoft Entra InternetPrivate Access license is required. For details, see the licensing section of What is Global Secure Access?.

  • The Reports Reader role is the least privileged role required to view scenario monitoring signals.signals, alerts, and alert configurations.

  • The Helpdesk Administrator is the least privileged role required to update alerts and update alert notification configurations.

  • The HealthMonitoringAlert.Read.All permission is required to view the alerts using the Microsoft Graph API.

  • The HealthMonitoringAlert.ReadWrite.All permission is required to view and modify the alerts using the Microsoft Graph API.

  • For a full list of roles, see Least privileged role by taskLeast privileged role by task.

  • The Global Secure Access Log Reader role of viewing the traffic logs in Microsoft Entra Internet Access andis required to view Microsoft Entra Private Access.Access traffic logs.

Investigate the signalssignal and alert

To investigate a signal, gatherStart your investigation by comparing the following data:alert timeframe, signal trend, and affected entities. Then correlate the affected users and applications with connector status and logs.

  1. View the details of the alert.

  2. Sign intoin to the Microsoft Entra admin center as at least a Reports ReaderReports Reader.

    • Browse to Entra ID > Monitoring & health > Health. The page opens to the Service Level Agreement (SLA) Attainment page.

    • Select the Health Monitoring tab.

    • Select the Private application access requiring Microsoft Entra Private Access connector scenario.scenario, and then select an active alert.

    :::image type="content" source="media/howto-investigate-private-access-connector-signals/private-access-alert.png" alt-text="Screenshot of the Private application access requiring Microsoft Entra Private Access connector scenario with one active alert." lightbox="media/howto-investigate-private-access-connector-signals/private-access-alert.png":::

  3. Review your Microsoft Entra Private Access connector status. Confirm that the connector and updater services are running. For more information, see Microsoft Entra private network connector maintenance.

  4. Review Microsoft Entra Private Accessthe connector groups and its assignmentstheir application assignments. Confirm that each affected application is assigned to the applications.a group with healthy connectors. For more information, see Microsoft Entra private network connector groups.

  5. Review sign-in logs.

    • the sign-in logs

    • . Look for affected users beingwho are blocked from signing in to the application.

  6. Review the Global Secure Access traffic logs. Filter the logs to the alert timeframe and affected user or application, and look for private application transaction failures.

  7. Review traffic the Global Secure Access audit logs for recent connector group or application assignment changes.

    :::image type="content" source="media/howto-investigate-private-access-connector-signals/global-secure-access-audit-logs.png" alt-text="Screenshot of audit logs filtered to the Global Secure Access service." lightbox="media/howto-investigate-private-access-connector-signals/global-secure-access-audit-logs.png":::

Understand the signal

An alert can indicate a change in the number of users or private applications that fail to connect because a connector isn't available.

  • Global Secure Access network traffic logs - Global Secure Access | Microsoft LearnA spike can indicate that one or more connectors became unavailable, a connector group lost capacity, or an application was assigned to the wrong connector group.

  • Look for privateA dip can indicate that connector availability recovered. It can also indicate that traffic or application traffic transaction failures.assignments changed.

Compare the alert start time with connector status, connector event logs, audit logs, and planned maintenance before you change the configuration.

Mitigate common issues

The following common issues can cause this alert. This list isn't exhaustive, but it provides a starting point for your investigation.

A connector is inactive or unavailable

A connector service might be stopped, its trust certificate might be expired, or the connector host might be unable to reach the Microsoft Entra service.

To investigate and mitigate the issue:

  1. In the alert, identify the affected users and private applications and note the alert start time.
  2. Browse to Global Secure Access > Connect > Connectors, and identify inactive connectors in the connector group that serves the affected applications.

  3. On each affected connector server, confirm that the connector and updater services are running.
  4. Run the Connector Diagnostics tool to check certificate validity, ports 80 and 443, outbound proxy configuration, certificate revocation list access, service state, and back-end endpoint access.
  5. Review audit logs.
  6. Confirm that the connector becomes active and that new traffic log entries no longer show connector-related transaction failures.

An application is assigned to the wrong connector group

The assigned connector group might not contain a healthy connector that can reach the affected application's network.

To investigate and mitigate the issue:

  1. In the alert, identify whether failures are concentrated on one or more applications.
  2. Review each affected application's connector group assignment.
  3. Confirm that the assigned group contains active connectors in a network that can reach the application's destination.
  4. Review the audit logs for a connector group or application assignment change near the alert start time.
  5. Restore the intended assignment, or add healthy connectors that can reach the application to the assigned group.
  6. Test access and confirm recovery in the traffic logs and health signal.

A connector group has insufficient capacity or resilience

A connector group with a single connector, sustained high utilization, or poor connectivity to the service or back-end applications can cause intermittent failures.

To investigate and mitigate the issue:

  1. Check whether the connector group has at least two active connectors for high availability.
  2. Review connector host CPU and network utilization. Keep sustained CPU and memory utilization below the documented thresholds.
  3. From each connector server, test connectivity to the affected back-end application.
  4. If a connector host is unavailable, remove it from active service and add a healthy or backup connector to the group.
  5. If utilization is sustained, add connectors or increase host capacity. For sizing and performance guidance, see Microsoft Entra private network connectors.
  6. Confirm that failures stop and the signal returns to its expected range.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…