How to configure Global Secure Access web content filtering
The documentation removes “preview” from the source traffic type and HTTP method request filtering conditions, updates their headings and links, and refreshes the page date.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra Internet Access.
Microsoft Learn documentation ↗The documentation removes “preview” from the source traffic type and HTTP method request filtering conditions, updates their headings and links, and refreshes the page date.
The documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.
The Internet Access health-signal article now lists licensing, roles, Microsoft Graph permissions, and log access requirements. It also adds steps for investigating alerts and reviewing filtering and forwarding policies.
Microsoft Purview DLP integrates with Entra Global Secure Access Internet Access to filter sensitive files at the network layer, preventing data leaks to unmanaged cloud apps. Public preview starts mid-November 2025; general availability by October 2026. Admins must configure policies, TLS inspection, and activate Purview pay-as-you-go.
The documentation now explains that V2 selects the first applicable profile containing a V2 policy, does not support user or group targeting on individual rules, and may produce different enforcement from V1 during migration.
A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.
The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.
The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.
Learn how to configure Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps side by side without proxying traffic twice.
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
Explicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.
With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).
Learn how to upload and host your own Proxy Auto-Configuration (PAC) files
Learn about bring your own device (BYOD) with the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Security operations guide for Microsoft Entra Global Secure Access covering detection patterns and Sentinel analytics for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.
At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deployment. You have met [licensing requirements](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview). You're ready to enable Microsoft Entra Internet Access.
Zscaler Internet Access Administrator is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSCloud is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSNet is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSOne is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSThree is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSTwo is available in the following [national cloud deployments](/graph/deployments).
This series of exercises covers the fundamentals of Internet Access. The exercises assume that you follow them in order. If you skip around, you might miss a step. For example, in the baseline web-filtering tutorial, you create a security profile and assign it to a Microsoft Entra Conditional Access policy. Subsequent labs instruct you to assign the new policy to this existing security profile rather than creating a new security profile and Conditional Access policy each time.
Learn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Learn how to monitor and investigate scenarios where internet applications are blocked by Microsoft Entra Internet Access policies, using Microsoft Entra Health monitoring tools.
Learn about bring your own device (BYOD) with the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Configure Microsoft Entra Suite products for strict default internet access policies to control internet access according to business requirements.
Microsoft Entra Internet Access will update web categorization in mid-June 2026, adding a new AI Agents category and refining existing ones. Some sites will be reclassified, affecting filtering policies. No action is required, but admins should review and adjust policies as needed.
Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |
Explicit Forward Proxy (EFP) allows you to use Secure Web and AI Gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access (GSA) client. EFP works with any browser that supports proxy automatic configuration (PAC).
*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.
1. Download the GSA client for Windows 11 from one of the following links. You can also use the [sample PowerShell script](scripts/powershell-windows-client-install-proof-of-concept.md).
Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.
Learn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
> 1. Client sees a certificate signed by your enterprise CA.
| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access.
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Deploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Configure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
ai-usage: ai-assisted
Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Learn how to configure threat intelligence in Microsoft Entra Internet Access.
Use custom block pages to display organization-specific messaging internet access policies block users from accessing websites.
With the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.
Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Deploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Configure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.
Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Learn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.
Microsoft Entra Internet Access's first Secure Web Gateway (SWG) features include web content filtering based on domain names. Microsoft integrates granular filtering policies with Microsoft Entra ID and Microsoft Entra Conditional Access, which results in filtering policies that are user-aware, context-aware, and easy to manage.
Create a Conditional Access policy for end users or groups and deliver your security profile through Conditional Access Session controls. Conditional Access is the delivery mechanism for user and context awareness for Internet Access policies. To learn more about session controls, see [Conditional Access: Session](/azure/active-directory/conditional-access/concept-conditional-access-session).
Global Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Learn about how Microsoft Entra Internet Access secures access to the Internet.
Learn about how Microsoft Entra Internet Access and Microsoft Entra Private Access secures access to your resources through Conditional Access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
PowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Learn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Learn how to configure threat intelligence in Microsoft Entra Internet Access.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.
Learn about how Microsoft Entra Internet Access secures access to the Internet.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
PowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
PowerShell examples for use in a Microsoft Entra Internet Access break glass scenario.
- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
Internet access traffic can be forwarded to the service by connecting through the [Global Secure Access desktop client](how-to-install-windows-client.md).
Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access uses a two-tier Intermediate certificate model to issue dynamically generated leaf certificates for decrypting traffic. This article explains how to configure the Certificate Authority (CA) that serves as the Global Secure Access intermediate CA, including signing and uploading the certificate.
:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::
The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.
- Select the **Internet applications blocked by Entra Internet Access Policy** scenario.
The Global Secure Access service is accessed from the Global Secure Access client and is used for Microsoft Entra Internet Access (including Microsoft 365) and Microsoft Entra Private Access traffic. The Internet Protocol (IP) addresses are listed.
1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).
The [Universal Conditional Access documentation](/entra/global-secure-access/concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authorization limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertently lock users out from accessing anything on their machine.
ai-usage: ai-assisted
1. **[Configuration 1: Microsoft Entra Private Access with Netskope Internet Access](#configuration-1-microsoft-entra-private-access-with-netskope-internet-access)**
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
Learn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the GSA Client in the Internet Access forwarding profile.
PowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.