Microsoft Entra Internet Access
Monitoring

How to investigate the internet applications blocked by Entra Internet Access policy

In brief

The Internet Access health-signal article now lists licensing, roles, Microsoft Graph permissions, and log access requirements. It also adds steps for investigating alerts and reviewing filtering and forwarding policies.

What Entra admins need to know

Administrators can use the clarified requirements and investigation workflow when monitoring alerts and diagnosing Internet Access issues.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

This article describes the health metrics related to internet applications blocked by Microsoft Entra Internet Access policies and how to troubleshoot a potential issue when you receive an alert.

This scenario:

  • Aggregates the number of unique users accessing internet applications successfully

    successfully.
  • Aggregates the number of unique users who failed to access internet applications.

  • Aggregates the number of unique internet applications accessed successfully

    successfully.
  • Aggregates the number of failed accesses to unique internet applications.

Prerequisites

There are different roles, permissions, and license requirements to view health monitoring signals and configure and receive alerts. We recommend using a role with least privilege access to align with the Zero Trust guidance.

  • A tenant with a Microsoft Entra P1 or P2 license is required to view the Microsoft Entra health scenario monitoring signals.

  • A tenant with both a non-trial Microsoft Entra P1 or P2 license and at least 100 monthly active users is required to view alerts and receive alert notifications.

  • A tenant with a Microsoft Entra Internet Access license is required. For details, see the licensing section of What is Global Secure Access?.

  • The Reports Reader role is the least privileged role required to view scenario monitoring signals.signals, alerts, and alert configurations.

  • The Helpdesk Administrator is the least privileged role required to update alerts and update alert notification configurations.

  • The HealthMonitoringAlert.Read.All permission is required to view the alerts using the Microsoft Graph API.

  • The HealthMonitoringAlert.ReadWrite.All permission is required to view and modify the alerts using the Microsoft Graph API.

  • For a full list of roles, see Least privileged role by taskLeast privileged role by task.

  • The Global Secure Access Log Reader role of viewing the traffic logs inis required to view Microsoft Entra Internet Access and Microsoft Entra Private Access.traffic logs.

Investigate the signal and alert

To investigate a signal, gatherStart your investigation by comparing the following data:alert timeframe, signal trend, and affected entities. Then correlate the affected users and applications with the traffic, sign-in, and audit logs.

  1. View the details of the alert.

  2. Sign intoin to the Microsoft Entra admin center as at least a Reports ReaderReports Reader.

    • Browse to Entra ID > Monitoring & health > Health. The page opens to the Service Level Agreement (SLA) Attainment page.

    • Select the Health Monitoring tab.

    • Select the Internet applications blocked by Entra Internet Access Policy scenario.scenario, and then select an active alert.

      :::image type="content" source="media/howto-investigate-internet-access-signals/internet-access-blocked.png" alt-text="Screenshot showing the Internet applications blocked by Entra Internet Access Policy scenario in the health monitoring dashboard." lightbox="media/howto-investigate-internet-access-signals/internet-access-blocked.png":::

  3. Review your Microsoft Entra Internet Access content filtering policies. Check the policy rules, linked security profiles, and Conditional Access assignments. For more information, see Configure Global Secure Access web content filtering.

  4. Review the Microsoft Entra Internet Access forwarding profile for accessprofile, including its acquire and bypass policies and user and group assignments. For more information, see Manage the Internet Access profile.

  5. Review sign-in logs. For more information, seethe sign-in logs. Look for affected users being blocked from signing in andwhose sign-ins have a Use Global Secure Access security profile.profile applied.

  6. Review the Global Secure Access traffic logs. Filter the logs to the alert timeframe and affected user or application. Review denied transactions and their web category.

    :::image type="content" source="media/howto-investigate-internet-access-signals/internet-access-traffic-logs.png" alt-text="Screenshot of Internet Access traffic logs showing blocked internet destinations." lightbox="media/howto-investigate-internet-access-signals/internet-access-traffic-logs. For more information, see Global Secure Access network traffic logs - Global Secure Access | Microsoft Learn.png":::

  7. Review the Global Secure Access audit logs for recent changes to filtering policies, security profiles, forwarding profiles, and assignments.

    :::image type="content" source="media/howto-investigate-internet-access-signals/global-secure-access-audit-logs.png" alt-text="Screenshot of audit logs filtered to the Global Secure Access service." lightbox="media/howto-investigate-internet-access-signals/global-secure-access-audit-logs. Forpng":::

Understand the signal

An alert can indicate a change in the number of users or internet applications that Microsoft Entra Internet Access policies block.

The change might be intentional. Compare the alert start time with the audit logs and your deployment schedule before you modify a policy.

Mitigate common issues

The following common issues can cause this alert. This list isn't exhaustive, but it provides a starting point for your investigation.

Many users are unexpectedly blocked after a policy or assignment change

A filtering policy, linked security profile, Conditional Access policy, or forwarding profile assignment might have expanded to include more users than intended.

To investigate and mitigate the issue:

  1. In the alert, compare the number of affected users and applications with your expected deployment scope.
  2. In the traffic logs, filter to the alert timeframe and an affected user. Confirm that the Action is Denied, and identify the destination and web category.
  3. Review the audit logs for changes made shortly before the alert started.
  4. Review the user and group assignments for the Internet Access forwarding profile and linked Conditional Access policy. Confirm that the Conditional Access session control selects the intended security profile.
  5. If the expanded scope is intentional, monitor the signal and no further action is required. If it isn't intentional, restore the intended assignments or policy scope.

A required application is blocked by a filtering rule

A web category, URL, FQDN, or wildcard rule might match a business application that users need. When multiple matching policies have conflicting actions, the most restrictive action applies.

To investigate and mitigate the issue:

  1. In the alert, identify an affected application and user.
  2. In the traffic logs, filter by the affected user and destination. Review the Action and Web category values for denied transactions.
  3. Review all filtering rules that match the destination. Check category rules, exact URLs or FQDNs, and wildcard entries.
  4. If the block is unintended, narrow the blocking rule or add the required destination to an appropriate allow policy. Keep the change limited to the users and destinations that require access.
  5. Allow time for the policy change to propagate, and then confirm that new traffic log entries show the expected action.

Only a subset of users is unexpectedly blocked

Different forwarding profile, security profile, or Conditional Access assignments can cause users who access the same application to receive different policy decisions.

To investigate and mitigate the issue:

  1. Compare traffic log entries for an affected user and an unaffected user accessing the same destination.
  2. Compare their user and group memberships and the assignments for the forwarding profile and linked Conditional Access policy. Confirm that the Conditional Access session control selects the intended security profile.
  3. Confirm that the Internet Access traffic forwarding profile is enabled and that its acquire and bypass policies match the intended traffic.
  4. Correct the unintended assignment or traffic acquisition rule, and then validate the result in the traffic logs.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…