Microsoft Entra Global Secure Access
General

Assign users and devices to traffic forwarding profiles

In brief

The article now documents assigning users, groups, devices, and device platforms to traffic forwarding profiles, including custom Private Access profiles. It also explains that user/device and platform conditions are evaluated together and that the highest-priority applicable profile is used.

What Entra admins need to know

Administrators can use these assignment rules to scope traffic forwarding more precisely across users and devices.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How to assignAssign users and groupsdevices to traffic forwarding profiles

Overview

With theYou can assign specific users, groups, devices, and device platforms to a Global Secure Access traffic forwarding features,profile. Assignments let you can assign specificdeploy a profile gradually and provide different traffic acquisition rules to different users and groups to a traffic forwarding profile. User or group assignment limits the scope of the traffic forwarding profile so you have a mechanism to roll out the profile safely and at a controlled pace.devices.

This article describes how to assign specific users and groups to aexplains assignments for traffic forwarding profile.profiles, including custom Private Access profiles.

Prerequisites

To assign a traffic forwarding profile to specific users and groups,manage assignments, you must have:

How assignments are evaluated

A traffic forwarding profile when assigned to the user.

Assign a traffic forwarding profile to specific users and groups

If you already enabled a traffic forwarding profile, the traffic profile is assigned to all users by default. If you haven't yet enabled a traffic forwarding profile, when you enable it the traffic is assigned to zero users. The has two assignment conditions:

  • User and groupdevice assignments setting lets you roll outdetermine which users, groups, or individual devices are in scope.
  • Device platform assignments determine which device platforms are in scope.

The conditions are evaluated with an AND. A device receives a profile only when it matches both conditions.

If multiple enabled profiles for the feature in a controlled mannersame traffic type apply to a specific set of users.

The screenshot illustrates the setting. The Microsoft profile is disabled and is assigned to zero users and groups. The Private Access and Internet Access profiles are enabled and are assigned to all users.

:::image type="content" source="media/how-to-manage-users-groups-assignment/traffic-profile-user-assignment-comparison.png" alt-text="Screenshot of the traffic forwarding page with user assignments highlighted." lightbox="media/how-to-manage-users-groups-assignment/traffic-profile-user-assignment-comparison-expanded.png":::

You can configure the user and group assignments before or after enablingdevice, only the traffic profile. You must enableapplicable profile with the traffic profile to acquirehighest priority is used.

Assign users, groups, and forward any traffic. For more information, see About traffic forwarding profiles.

Assign users and groups to a traffic profile

devices
  1. Sign in to the Microsoft Entra admin center as a Global Secure Access Administrator AND Application Administrator.Global Secure Access Administrator and Application Administrator.

  2. Browse to Global Secure Access > Connect > Traffic forwarding.

  3. Select the View link in the User and group assignments section.

    Screenshot that shows the traffic forwarding profiles with the view link highlighted.

  4. Select the 0 Users, 0 Groups assigned link.

    Screenshot that shows the 0 users, 0 groups assigned link.traffic forwarding profile.

  5. Select Add user/groupAssignments.

    Screenshot that shows the users and groups page with the Add user/group button highlighted.

  6. Select the None selected link, select the users and/or groups from the list, and select the Select button.

    • The All list groups users and groups together. Select either the Users or Groups tabNext to narrow the list.
    • You can also use the Search box to find the user or group directly.

    Screenshot that shows the user/group selection process with the None selected link highlighted.

  7. Select the Assign button.

Change existing user and group assignments

The process to change the user and group assignments for a traffic profile that's already enabled is very similar except for the following steps.

  1. When you select the View link in the User and groupdevice assignments section, you need to change the, select Assign to all users setting to No.

    Screenshot that shows the Assign to all users toggle.

  2. Review the confirmation message, and select the OK button.

    Screenshot that shows the confirmation message.

  3. Continue with the steps in the previous section.

Automatic assignment through user attributes

You can create and assign a dynamic group of users to the profile who satisfy specific criteria. For more information about automatic assignment using user attributes, see Create or update a dynamic group in Microsoft Entra ID.

Assign the traffic profile to all users

Once you assign a traffic forwarding profile to a specific user or group, you can quickly change the setting to scope the traffic profile to all users. If you change it back again to a specific group, any users and groups initially assigned to that traffic forwarding profile are retained so you don't need to add them again.

  1. Browse to Global Secure Access > Connect > Traffic forwardingView.

  2. Select one of the following options:

    • ViewNo users and devices link: The profile isn't assigned through the Global Secure Access client.
    • All users and devices: All devices with the Global Secure Access client are in scope, subject to the device-platform assignment.
    • userSelected users and group assignmentsdevices section.: Select specific users, groups, or devices.

    Screenshot of the Edit user and device assignments pane with All users and devices selected.

  3. Change theIf you selected Assign to allSelected users toggle to Yes and devices, review the confirmation message, and select the OK button.

    Screenshot that shows the assign to all users confirmation message.

  4. Selectassignment link, choose the Done button.

Revert all users assignment back to a specific user or group

You can revert the assignment of all users to a traffic profile. When you toggle off the assignment for all users, you revert to the usersgroups, and groups that were assigned when you toggled it on.

  1. Browse todevices, and then select Global Secure Access > Connect > Traffic forwardingSelect.

  2. Select the View link in the user and group assignments section.

  3. Change the Assign to all users toggle to No, review the confirmation message, and select the OK button.

  4. Select DoneSave.

Notes on user identity and groupAssign device platforms

  1. From the profile's Assignments page, select View next to Device platform assignments.
  2. Select the device platforms that should receive the profile.
  3. Select Save.

You can combine platform assignment

Review the following notes to better understand the with user and device assignment. For example:

  • Assign All users and devices and select iOS to apply the profile to all iOS devices with the Global Secure Access client.
  • Assign a user group and select Windows and macOS to apply the profile only to desktop devices used by members of that group.

Assignment evaluation examples

User and device assignmentsDevice platform assignmentsResult
All users and devicesAll device platformsAll devices with the Global Secure Access client receive the profile.
All users and devicesWindows and macOSAll Windows and macOS devices with the client receive the profile.
All users and devicesNoneNo devices receive the profile.
Five users and two devicesAll device platformsAll client devices used by the five users and the two selected devices receive the profile.
Five users and two devicesAndroidAndroid client devices used by the five users and the selected devices receive the profile only if those devices are Android devices.
No users, groups, or devicesAny platformNo devices receive the profile.

Assign a profile to all devices on a platform

To assign a profile to all devices on a specific platform:

  1. Set User and device assignments to All users and devices.
  2. Under Device platform assignments, select only the target platform.
  3. Save both assignment capabilities.settings.

Automatic assignment through user attributes

You can assign a dynamic group whose members satisfy specific user criteria. For more information, see Create or update a dynamic group in Microsoft Entra ID.

Validate the effective profile

  1. Sign in to a registered device as a user included in the assignment.
  2. Right-click the Global Secure Access client, and then select Advanced diagnostics > Forwarding profile.
  3. Expand the applicable traffic type, such as Private Access rules.
  4. Confirm that the expected application segments appear.

If more than one profile could apply, confirm that the profile with the highest priority is effective.

Notes about identity, groups, and devices

  • Traffic profiles are fetched on behalf offor the Microsoft Entra user logged intosigned in to the device​,device, not the user logged intosigned in to the client​. client.
  • If there's no Microsoft Entra user loggedis signed in, the traffica profile is fetched only if it's assigned to all users. For example, if you log into the device as a local admin you're part of the all users.when All users and devices is selected.
  • Multiple users logging intosigned in to the same device simultaneously isnaren't supported.
  • Group-basedGroup assignment is supported for Securitysupports security groups and Microsoft 365 groups whose SecurityEnabled settingnested group membership is set to True.
  • Nested group memberships aren't supported. A user must be a direct member of the group assigned to the profile.

Next steps

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…