How to configure custom HTTP headers in Global Secure Access
The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra Global Secure Access.
Microsoft Learn documentation ↗The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.
The article now distinguishes tunnel and BGP connectivity scenarios and adds investigation steps, licensing requirements, least-privilege roles, and Microsoft Graph permissions for viewing and managing signals and alerts.
The documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”
The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.
Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.
The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.
The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.
The page title now marks custom headers as preview and notes that rollout is expected to complete by September 10, 2026.
The AI prompt injection protection documentation now explains that TLS inspection can use either a Microsoft-managed certificate or an administrator-provided certificate before configuring TLS inspection policies.
The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.
The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.
The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.
The documentation now provides separate links for configuring TLS inspection with a Microsoft-managed certificate and with your own certificate.
New documentation describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. The capability is currently in preview and supports tenant restrictions and other header-aware services.
The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.
The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.
The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.
The documentation received a minor formatting change with no substantive content changes identified.
The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.
Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.
The Netskope integration example now uses different values for the tenantId and userId fields.
The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.
The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.
The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.
The release-history page no longer includes version 1.1.26060207 or its listed changes, and its document date changed from August 21, 2026, to April 16, 2026.
The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.
The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.
The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.
The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.
The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.
Starting with version 1.1.26060207, the app package includes com.microsoft.autoupdate2 for future use cases.
The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.
The guide now presents the V1-to-V2 migration procedure and migration options as numbered steps.
A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.
The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.
The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”
The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.
Microsoft added a how-to article for configuring the Global Secure Access MCP firewall to inspect, audit, and allow or block Model Context Protocol traffic. It covers server, primitive, method, and protocol-version controls for supported MCP traffic.
The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).
Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.
You can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge by using an Intune mobile application management (MAM) policy. The policy can take advantage of the Explicit Forward Proxy feature of Global Secure Access.
Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:
Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).
- [Global Secure Access traffic forwarding profiles](concept-traffic-forwarding.md)
- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time.
Learn how to configure universal tenant restrictions with Global Secure Access for Microsoft traffic.
Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.
Learn how to configure a Conditional Access policy that requires a compliant network with Global Secure Access.
Learn how to enable the Microsoft traffic profile in Global Secure Access, assign users, install the client, and verify traffic forwarding.
Learn about Microsoft traffic labs for Global Secure Access, including source IP restoration, compliant network checks, and universal tenant restrictions.
Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
Calculate the Microsoft Sentinel alert noise ratio for Global Secure Access detections and send an alert when false positives or informational closures exceed your threshold.
Check Global Secure Access-related administrator role assignments and identify accounts that need quarterly review.
List Microsoft Entra Backup and Recovery snapshots that can help recover directory objects used by Global Secure Access.
Create a non-destructive Microsoft Entra recovery preview job scoped to directory objects that affect Global Secure Access.
Run a Microsoft Entra recovery job for directory objects that affect Global Secure Access after reviewing a recovery preview.
Use shared helper functions for authentication and alert email in Global Secure Access operations automation scripts.
Verify that your Global Secure Access configuration backup runbook ran successfully. Send an alert when the runbook fails or misses a scheduled run.
Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.
- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)
1. Create end user communications to set expectations and provide an escalation path.
- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)
- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)
Learn how AI agent discovery in Global Secure Access provides network-level visibility into managed and shadow AI agents reaching the internet from your environment.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Use Application discovery to detect the applications accessed by users and create separate private applications.
Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.
Learn how to configure a Conditional Access policy for Explicit Forward Proxy.
Learn how to configure HTTP header session management for Explicit Forward Proxy.
A Microsoft Entra documentation page was updated: Configure Microsoft Edge with Explicit Forward Proxy (preview) by using an Intune application management policy.
Learn how to configure Secure Web and AI Gateway for Microsoft Copilot Studio agents using Global Secure Access.
Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Learn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.
Learn how to set up the bidirectional communication tunnel between Global Secure Access and your router.
The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the macOS client.
Use Global Secure Access to configure Azure and Microsoft Entra resources to create a virtual wide area network to connect to your resources in Azure.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.
This article provides techniques to improve remote network resilience with Global Secure Access.
Learn about Explicit Forward Proxy session management concepts.
Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.
Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.
Global Secure Access maintains a compliance portfolio. This article lists the current, supported certifications.
Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.
Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
Learn how to add and delete customer premises equipment device links to remote networks for Global Secure Access.
Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.
Learn how to monitor and troubleshoot remote network connectivity using Microsoft Entra Health monitoring.
Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
A Microsoft Entra documentation page was updated: Install Android Client.
The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the Windows client.
Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.
Learn about Explicit Forward Proxy PAC file concepts.
Understand critical IP address ranges to consider when configuring and troubleshooting internet over remote network connectivity.
Discover the known limitations of Global Secure Access, including platform-specific issues and mitigations, to ensure seamless deployment and management.
Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.
Learn how Global Secure Access enables secure external user access for partners through the Global Secure Access client and Azure Virtual Desktop.
Learn about the features and benefits of our Secure Web and AI Gateway for agents in Global Secure Access.
This article tracks the release notes and download instructions for the Global Secure Access client for macOS.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.