Microsoft Entra Global Secure Access
General

Known limitations for Global Secure Access

In brief

The known limitations article now states that the client doesn't support Secure DNS variants such as DoH, DoT, or DNSSEC, and that the macOS client bypasses Secure DNS to enforce FQDN-based tunneling.

What Entra admins need to know

Administrators should account for this limitation when planning deployments involving Secure DNS or FQDN-based tunneling.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Known limitations for Global Secure Access

Known limitations for the Global Secure Access client for macOS include:

Secure Domain Name System (DNS)

IfThe Global Secure Access client doesn't currently support secure DNS in its different versions, such as DNS over HTTPS (DoH), DNS over TLS (DoT), or DNS Security Extensions (DNSSEC). The client for macOS bypasses Secure DNS is enabled onto enforce fully qualified domain name (FQDN)-based tunneling through the traffic forwarding policy. You don't need to disable Secure DNS in the browser or in macOS and the DNS server supports Secure DNS, then the client doesn't tunnel traffic set to be acquired by FQDN. (Network traffic that's acquired by IP isn't affected and is tunneled according to the forwarding profile.) To mitigate the Secure DNS issue, disable Secure DNS, set a DNS server that doesn't support Secure DNS, or create rules based on IP.macOS.

Connection fallback

If there's a connection error to the cloud service, the client falls back to either direct Internet connection or blocking the connection, based on the hardening value of the matching rule in the forwarding profile.

  • On MacOS, coexistence of GSA client and EFP settings are not supported due to client certificate issues.
  • Microsoft Office 365 traffic should not be tunneled to EFP. EFP-hosted PAC file excludes Office 365 destinations. Office 365 traffic is defined in the Microsoft 365 IP and FQDN list
  • EFP supports Microsoft Entra Internet Access traffic type. Private Access and Microsoft Traffic are not supported when users configure EFP.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…