Product

Microsoft Entra Global Secure Access

Track documentation and Message Center changes for Microsoft Entra Global Secure Access.

Microsoft Learn documentation ↗

Latest Microsoft Entra Global Secure Access changes

Learn about Universal Continuous Evaluation

Fundamentals

The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.

Generative Ai Insights

Fundamentals

The documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

How to configure custom headers (preview)

General

The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.

Configure Custom Headers

General

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

Configure TLS inspection with a Microsoft-managed certificate

Security

The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.

Configure TLS inspection with your own certificate

Security

The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.

Transport Layer Security

Security

The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.

Troubleshoot App Access

Troubleshooting

The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.

Troubleshoot Transport Layer Security

Troubleshooting

The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.

How to configure custom HTTP headers in Global Secure Access

General

New documentation describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. The capability is currently in preview and supports tenant restrictions and other header-aware services.

Version History

General

The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.

Version History

General

The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.

Current Known Limitations

General

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

Current Known Limitations

General

The documentation received a minor formatting change with no substantive content changes identified.

Current Known Limitations

General

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

Global Secure Access Client Release Notes

General

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

Netskope Integration

Fundamentals

The Netskope integration example now uses different values for the tenantId and userId fields.

Global Secure Access Client for macOS Release Notes

General

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

Install the Global Secure Access Client for macOS

General

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

Macos Client Release History

General

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

Global Secure Access Client for macOS Release Notes

General

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

Install Macos Client

General

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

Install Macos Client

General

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

Install Macos Client

General

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

Install the Global Secure Access Client for macOS

General

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

Macos Client Release History

General

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

Migrate web content filtering policies from V1 to V2

General

A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.

Web Filtering

Fundamentals

The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.

Manage Microsoft Profile

General

The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”

Manage Microsoft Profile

General

The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.

Network Content Filtering

General

The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.

Configure Per App Access

Microsoft identity platform

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

Global Secure Access egress IP ranges

General

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

Configure Web Content Filtering

General

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

Universal Tenant Restrictions

Authentication

- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.

Configure HTTP header session management (preview)

Authentication

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

Explicit Forward Proxy overview

Fundamentals

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

Explicit Forward Proxy session management

Conditional Access

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Proxy Automatic Configuration Files

Fundamentals

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

Configure Web Content Filtering

General

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

Tutorial: Enable source IP restoration

Authentication

Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.

PowerShell samples for Global Secure Access

Monitoring

Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.

Security Operations

Security

- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)

Operations

Fundamentals

| Guide | What it covers |

Universal Tenant Restrictions

General

- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)

Universal Tenant Restrictions

General

- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)

Ai Prompt Injection Protection

Security

Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.

Application Discovery

Developer

Use Application discovery to detect the applications accessed by users and create separate private applications.

Application Usage Analytics Overview

Fundamentals

Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.

Export Connector Logs

Monitoring

Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.

How to Create Remote Networks

General

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

Install Android Client

General

A Microsoft Entra documentation page was updated: Install Android Client.

Install Ios Client

General

A Microsoft Entra documentation page was updated: Install Ios Client.

Install Windows Client

General

The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the Windows client.

Known Limitations for Global Secure Access

General

Discover the known limitations of Global Secure Access, including platform-specific issues and mitigations, to ensure seamless deployment and management.

Learn about Global Secure Access Alerts

Fundamentals

Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.

Macos Client Release History

General

This article tracks the release notes and download instructions for the Global Secure Access client for macOS.

Network Content Filtering

Security

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…