Multi-Geo for Microsoft Entra Private Access
In brief
The guide now consistently spells “Multi-Geo,” including correcting a typo in the Japan region limitation.
What Entra admins need to know
Administrators can follow the clarified terminology; no action is required.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Multi-Geo for Microsoft Entra Private Access
description: "Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps."
ms.topic: how-to
ms.date: 08/18/2025
ms.reviewer: katabish
Prerequisites
- You must have a Microsoft Entra Private Access license.
- You must have a Microsoft Entra Private Access connector group. For more information, see How to configure private network connectors for Microsoft Entra Private Access and Microsoft Entra application proxy.
- You must have the Global Secure Access Administrator role or the Privileged Role Administrator role. For more information, see Microsoft Entra Built-in Roles.
Overview
To enable the multi-Geo capability for Microsoft Entra Private Access, complete the following steps. This procedure involves creating connector group in different geographic region, installing connectors, and adding application segments to the connector group.
- Sign in to the Microsoft Entra admin center as a Global Secure Access Administrator.
- Browse to Applications > Enterprise applications > Private Network connectors.
- Create a connector group, associate it with a geographic region of your choice.
- Select + New Connector Group.
- In the New Connector Group pane, enter a name for the connector group.
- Under Advanced settings, select the optimized country/region for the connector group. The region you select determines the backend that the connector group connects to.
- Install a connector. The connector installation require working with an admin in the associated region. For more information, see How to configure private network connectors for Microsoft Entra Private Access and Microsoft Entra application proxy.
- Add an application segment to the connector group.
- Browse to Global Secure Access > Applications > Enterprise applications > Network access properties.
- Select + Add application segment.
- Select the application segment you want to add to the connector group.
- Select Save.
- After about 30 minutes, the multi-Geo configuration takes effect and traffic begins flowing.
Related content
@@ -1,7 +1,7 @@ --- title: Multi-Geo for Microsoft Entra Private Access description: "Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps."-ms.topic: how-to +ms.topic: how-to ms.date: 08/18/2025 ms.reviewer: katabish @@ -13,9 +13,9 @@ Multi-Geo capability can help optimize the traffic flow from Microsoft Entra cli ## Prerequisites -- You must have a Microsoft Entra Private Access license. -- You must have a Microsoft Entra Private Access connector group. For more information, see [How to configure private network connectors for Microsoft Entra Private Access and Microsoft Entra application proxy](how-to-configure-connectors.md). -- You must have the **Global Secure Access Administrator** role or the **Privileged Role Administrator** role. For more information, see [Microsoft Entra Built-in Roles](../identity/role-based-access-control/permissions-reference.md). +- You must have a Microsoft Entra Private Access license.+- You must have a Microsoft Entra Private Access connector group. For more information, see [How to configure private network connectors for Microsoft Entra Private Access and Microsoft Entra application proxy](how-to-configure-connectors.md).+- You must have the **Global Secure Access Administrator** role or the **Privileged Role Administrator** role. For more information, see [Microsoft Entra Built-in Roles](../identity/role-based-access-control/permissions-reference.md). ## Overview @@ -27,23 +27,23 @@ Multi-Geo capability helps optimize traffic flow from Microsoft Entra clients to To enable the multi-Geo capability for Microsoft Entra Private Access, complete the following steps. This procedure involves creating connector group in different geographic region, installing connectors, and adding application segments to the connector group. 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).-1. Browse to **Applications** > **Enterprise applications** > **Private Network connectors**. -1. Create a connector group, associate it with a geographic region of your choice. - 1. Select **+ New Connector Group**. +1. Browse to **Applications** > **Enterprise applications** > **Private Network connectors**.+1. Create a connector group, associate it with a geographic region of your choice.+ 1. Select **+ New Connector Group**. 1. In the **New Connector Group** pane, enter a name for the connector group.- 1. Under Advanced settings, select the optimized **country/region** for the connector group. The region you select determines the backend that the connector group connects to. -1. Install a connector. The connector installation require working with an admin in the associated region. For more information, see [How to configure private network connectors for Microsoft Entra Private Access and Microsoft Entra application proxy](how-to-configure-connectors.md). -1. Add an application segment to the connector group. - 1. Browse to **Global Secure Access** > **Applications** > **Enterprise applications** > **Network access properties**. + 1. Under Advanced settings, select the optimized **country/region** for the connector group. The region you select determines the backend that the connector group connects to.+1. Install a connector. The connector installation require working with an admin in the associated region. For more information, see [How to configure private network connectors for Microsoft Entra Private Access and Microsoft Entra application proxy](how-to-configure-connectors.md).+1. Add an application segment to the connector group.+ 1. Browse to **Global Secure Access** > **Applications** > **Enterprise applications** > **Network access properties**. 1. Select **+ Add application segment**.- 1. Select the application segment you want to add to the connector group. - 1. Select **Save**. -1. After about 30 minutes, the multi-Geo configuration takes effect and traffic begins flowing. + 1. Select the application segment you want to add to the connector group.+ 1. Select **Save**.+1. After about 30 minutes, the multi-Geo configuration takes effect and traffic begins flowing. > [!NOTE]-> - Multi-Geo connectors aren't available through Quick Access. Multi-Geo supports only private enterprise apps. +> - Multi-Geo connectors aren't available through Quick Access. Multi-Geo supports only private enterprise apps. > - Multi-Geo doesn't support the Domain Name System (DNS) experience.-> - Mulit-Geo doesn't support Japan region selection through Microsoft Entra admin center. +> - Multi-Geo doesn't support Japan region selection through Microsoft Entra admin center. ## Related content 