Microsoft Entra Private Access
General

Manage Private Access traffic forwarding profiles

In brief

Documentation now describes default and custom profiles, including profile settings, assignments, prerequisites, and a preview limit of 10 custom profiles.

What Entra admins need to know

Administrators can provide different private application access to specific users, devices, or groups. Application Administrator and Conditional Access Administrator roles, plus applicable licensing, are required to manage profiles.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How to manage theManage Private Access traffic forwarding profileprofiles

Overview

The Private Access traffic forwarding profile routesprofiles route traffic to your private network throughfrom the Global Secure Access Client.client to private resources. Enabling this traffic forwarding profile allows remote workers to connect to internal resources without a VPN. With the features of Microsoft Entra Private Access, you can control which private resources to tunnel through the service and apply Conditional Access policies to secure access to those services. Once your configurations are in place,You can use the default Private Access profile or create custom profiles with different applications, assignments, device platforms, priorities, and status.

Multiple profiles let you can viewprovide different private application access to internal and manage all of those configurations from one place.external users, desktop and mobile devices, or other groups with distinct access requirements.

Prerequisites

To enable themanage Private Access traffic forwarding profile for your tenant,profiles, you must have:

Known limitations

[!INCLUDE known-limitations-include]

Enable the

During preview:

  • You can create up to 10 custom Private Access traffic forwarding profiles.
  • A Private Access application must be included in the default Private Access profile before it can be selected for a custom profile.

View Private Access profiles

  1. Sign in to the Microsoft Entra admin center as a Global Secure Access Administrator.Global Secure Access Administrator.
  2. Browse to Global Secure Access > Connect > Traffic forwarding.

The page displays the system-created profiles and any custom profiles. Select a profile name to manage its Basics, Acquisition rules, and Assignments.

To add a custom profile, see Create a Private Access traffic forwarding profile.

Manage profile settings

Select Basics to update the custom profile's name, description, priority, or status.

Priority determines which profile is effective if multiple Private Access profiles apply to the same user and device. Only the applicable profile with the highest priority is used by the client.

Manage acquisition rules

Acquisition rules determine which private resources are included in a profile.

  1. Select the Private Access profile.

  2. Select Acquisition rules.

  3. Configure whether the profile includes Quick Access.

  4. Select the applications link to add or remove Private Access applications.

    Screenshot of the Acquisition rules page for a custom Private Access profile.

Use Select all to include all available applications, and then remove the applications that shouldn't be part of the profile.

Associate an application with multiple profiles

You can also manage profile associations from the Private Access application:

  1. Browse to Global Secure Access > Applications > Enterprise applications.
  2. Select the checkbox forapplication, and then select Private Access profileNetwork access properties.
  3. Select Manage attached profiles.
  4. Select one or more profiles, and then select Save.

Private Access policies

To enable theAn application can be associated with multiple Private Access traffic forwarding profile, it's recommendedprofiles.

Manage profile assignments

Select Assignments to first configure Quick Access. Quick Access includesconfigure:

  • User and device assignments: Assign no users or devices, all users and devices, or selected users, groups, and devices.

  • Device platform assignments: Select the IP addresses, IP ranges, and fully qualified domain names (FQDNs) fordevice platforms that receive the private resources you want to include in the policy.profile.

    Screenshot of the Assignments page showing user and device assignments and device platform assignments.

The two assignment conditions are evaluated together. For more information, see Configure Quick Access.

You can also configure per-app access to your private resources by creatingexample, if a Private Access app. Similar to Quick Access, you create a new Enterprise app, which can then beprofile is assigned to selected users and the Private Access traffic forwardingAndroid platform, only Android devices used by those selected users receive the profile. Quick Access contains the main group of private resources you always want to route through the service. Private Access apps can be enabled and disabled as needed without impacting the FQDNs and IP addresses included in Quick Access.

To manage the details included in the Private Access traffic forwarding policy, select the View link for Private Access policies.

Screenshot that shows the Private Access profile, with the view applications link highlighted.

Details of your Quick AccessFor detailed steps and enterprise apps for Private Access are displayed. Select the link for the application to view the details from the Enterprise applications area of Microsoft Entra ID.assignment examples, see Assign users and devices to traffic forwarding profiles.

Linked Conditional Access policies

Conditional Access policies for Private Access are configured at the application level for each app.level. You can create and apply a Conditional Access policies can be created and applied to the applicationpolicy from two places:either location:

  • GoBrowse to Global Secure Access > Applications > Enterprise applications. Select an applicationapplication, and then select Conditional Access from the side menu..
  • GoBrowse to Entra ID > Conditional Access > Policies. Select, and then select + Create newNew policy.

For more information, see Apply Conditional Access policies to Private Access applications.

User and group assignmentsDelete a custom profile

You can scope theCustom Private Access profiles can be deleted. The system-created default profile to specific users and groups. The users and groups mustcan't be assigned to both the Private Access apps and the traffic forwarding profile.deleted. Deleted custom profiles can't be restored.

For more information about user and group assignment,detailed steps, see How to assign and manage users and groups with traffic forwarding profilesDelete a Private Access traffic forwarding profile.

Next steps

The next step for getting started with Microsoft Entra Internet Access is to install and configure the Global Secure Access Client on end-user devices.

For more information about Private Access, see the following articles:

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…