Product

Microsoft Entra Global Secure Access

Track documentation and Message Center changes for Microsoft Entra Global Secure Access.

Microsoft Learn documentation ↗

Latest Microsoft Entra Global Secure Access changes

Version History

General

The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.

Version History

General

The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.

Current Known Limitations

General

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

Current Known Limitations

General

The documentation received a minor formatting change with no substantive content changes identified.

Current Known Limitations

General

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

Global Secure Access Client Release Notes

General

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

Netskope Integration

Fundamentals

The Netskope integration example now uses different values for the tenantId and userId fields.

Global Secure Access Client for macOS Release Notes

General

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

Install the Global Secure Access Client for macOS

General

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

Macos Client Release History

General

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

Global Secure Access Client for macOS Release Notes

General

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

Install Macos Client

General

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

Install Macos Client

General

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

Install Macos Client

General

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

Install the Global Secure Access Client for macOS

General

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

Macos Client Release History

General

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

Migrate web content filtering policies from V1 to V2

General

A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.

Web Filtering

Fundamentals

The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.

Manage Microsoft Profile

General

The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”

Manage Microsoft Profile

General

The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.

Network Content Filtering

General

The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.

Configure Per App Access

Microsoft identity platform

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

Global Secure Access egress IP ranges

General

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

Configure Web Content Filtering

General

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

Universal Tenant Restrictions

Authentication

- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.

Configure HTTP header session management (preview)

Authentication

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

Explicit Forward Proxy overview

Fundamentals

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

Explicit Forward Proxy session management

Conditional Access

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Proxy Automatic Configuration Files

Fundamentals

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

Configure Web Content Filtering

General

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

Tutorial: Enable source IP restoration

Authentication

Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.

PowerShell samples for Global Secure Access

Monitoring

Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.

Security Operations

Security

- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)

Operations

Fundamentals

| Guide | What it covers |

Universal Tenant Restrictions

General

- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)

Universal Tenant Restrictions

General

- [Enable Global Secure Access signaling for Microsoft Entra ID and Microsoft Graph](how-to-source-ip-restoration.md#enable-global-secure-access-signaling-for-microsoft-entra-id-and-microsoft-graph)

Ai Prompt Injection Protection

Security

Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.

Application Discovery

Developer

Use Application discovery to detect the applications accessed by users and create separate private applications.

Application Usage Analytics Overview

Fundamentals

Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.

Export Connector Logs

Monitoring

Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.

How to Create Remote Networks

General

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

Install Android Client

General

A Microsoft Entra documentation page was updated: Install Android Client.

Install Ios Client

General

A Microsoft Entra documentation page was updated: Install Ios Client.

Install Windows Client

General

The Global Secure Access client helps secure network traffic at the user device. This article describes how to download and install the Windows client.

Known Limitations for Global Secure Access

General

Discover the known limitations of Global Secure Access, including platform-specific issues and mitigations, to ensure seamless deployment and management.

Learn about Global Secure Access Alerts

Fundamentals

Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.

Macos Client Release History

General

This article tracks the release notes and download instructions for the Global Secure Access client for macOS.

Network Content Filtering

Security

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.

Shadow AI discovery in Global Secure Access

Fundamentals

Learn how Shadow AI discovery in Global Secure Access provides network-based visibility into unsanctioned AI applications and tools used in your organization.

Troubleshoot application access

Troubleshooting

Learn how to troubleshoot application access problems with the Global Secure Access Windows client.

Troubleshoot prompt injection protection

Troubleshooting

Reduce risk from malicious or manipulated prompts sent to generative AI sites and apps with prompt injection protection policies in Global Secure Access.

What is Transport Layer Security Inspection?

Fundamentals

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

Windows Client Release History

General

This article tracks the changes in each released version of the Global Secure Access client for Windows.

External User Access

Fundamentals

:::image type="content" source="media/concept-external-user-access/guest-access-overview.png" alt-text="Diagram showing an overview of external user access in Global Secure Access." lightbox="media/concept-external-user-access/guest-access-overview.png":::

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…