← Back to blog
Cloud & Infrastructure

Microsoft Global Secure Access: replacing your VPN with identity-first ZTNA via Entra Private Access

By Zarioh Digital Solutions6 min read
Share
Microsoft Global Secure Access: replacing your VPN with identity-first ZTNA via Entra Private Access

Traditional VPNs give users overly broad network access and create significant risk when an attack succeeds. Microsoft Global Secure Access offers identity-first VPN replacement through Entra Private Access, integrating with Conditional Access. What is it, how does it work, and how do you start migrating?

VPN has existed for more than thirty years. The technology was designed for a different era, when virtually all data and applications lived inside the office network and working from home was exceptional. In 2026, that assumption no longer holds. Applications run in the cloud, employees work from everywhere, and the network itself has become an attack surface.

Microsoft offers with Global Secure Access a Security Service Edge platform that replaces VPN with an identity-driven approach. Two components are central: Entra Private Access as the VPN replacement for access to private resources, and Entra Internet Access as an identity-aware secure web gateway for all internet traffic. Both operate under the same Conditional Access umbrella.

The problem with traditional VPN

A VPN gives a logged-in user access to the network, not just to the application they need. If an attacker obtains the VPN credentials of one employee, that attacker has access to everything on the network: file shares, RDP sessions, legacy applications, internal APIs. This is called lateral movement and is the core of how modern ransomware attacks operate.

Additionally, traditional VPNs lack contextual awareness. They do not check whether the device is compliant, whether there is an elevated risk signal, or whether the login comes from an unusual location. Once connected, you stay connected until the session expires, even if there is reason in the meantime to revoke access.

What is Microsoft Global Secure Access?

Global Secure Access is Microsoft's Security Service Edge solution, housed within Microsoft Entra. The platform consists of three components. Entra Internet Access is an identity-aware Secure Web Gateway that routes all internet and SaaS traffic from users through the Microsoft backbone network. Category filtering, URL logging, and Conditional Access also apply to internet sessions.

Entra Private Access is the actual VPN replacement: a Zero Trust Network Access layer that connects users to specific private resources, such as an internal file server, an RDP host, or a legacy web application, without them ever seeing the broader network. The user gets access to exactly what the policy permits and nothing more.

Microsoft Tunnel is the third component: a per-app mobile VPN for managed iOS and Android devices that gives Intune-managed apps access to internal resources. All three components work together and are managed from a single portal within Microsoft Entra.

Entra Private Access: how the VPN replacement works

The architecture of Entra Private Access revolves around Private Network Connectors. You install a lightweight connector on a server in your on-premises network or datacenter. That connector builds an outbound connection to the Microsoft Entra cloud — no inbound ports needed, no firewall exceptions. Users connect via the Global Secure Access client on their device, and Microsoft handles the secure tunnel.

You then define applications, not network segments. Quick Access is the most straightforward starting point: you specify IP ranges and FQDNs reachable via Private Access, similar to split tunneling but with full identity control layered on top. Per-app applications go further: you link one specific application to one connector group, so users with access to that app see nothing else.

At every connection attempt, Conditional Access re-verifies whether the user and device meet the requirements. An employee whose device is no longer compliant is automatically blocked, even if the connection was established earlier. That is structurally different from a traditional VPN session that continues until timeout.

Entra Internet Access: secure browsing via the Microsoft network

Entra Internet Access routes all internet traffic from managed devices through the Microsoft Security Service Edge. This brings two concrete advantages. First, traffic runs over the Microsoft backbone network, which improves latency and makes the traffic visible for security analysis. Second, Conditional Access now applies to internet traffic as well, something that was impossible in a traditional setup.

Concretely, you can configure that only Intune-compliant devices have access to certain website categories, that risky domains are blocked for specific user groups, and that all internet activity is logged in Microsoft Entra or forwarded to Microsoft Sentinel. It is the same policy engine as for Microsoft 365 access, extended to the full internet.

One Conditional Access policy layer for everything

The strongest asset of Global Secure Access is the integration with Conditional Access. In a traditional environment, Conditional Access is limited to Microsoft 365 apps and Azure services. With Global Secure Access, that policy extends to private applications and internet traffic. One policy, one logging location, one place to grant an exception or revoke a session.

This also makes incident response more effective. If a user account is compromised, revoking the session in Entra simultaneously interrupts access to Microsoft 365, the private business applications, and internet traffic through the gateway. With a traditional VPN, those are three separate actions in three separate systems, carried out by perhaps three different administrators.

Licensing: what does your organisation need?

Entra Private Access and Entra Internet Access are separate products on top of a Microsoft Entra ID P1 licence. The most practical way to access them is through the Entra Suite, a bundle that also includes Entra ID Governance, Identity Protection, and Verified ID. The Entra Suite is available as a standalone add-on on top of an existing Microsoft 365 licence.

Organisations on Microsoft 365 E7, the new top-tier package available since May 2026, already have the Entra Suite included. For organisations on E3 or E5, the Entra Suite or a standalone Private Access licence is a separate purchase. Private Access is also available as a standalone per-user per-month licence on top of P1.

Step by step towards a VPN-free network

A phased approach is the lowest-risk route. In the first phase, you install a Private Network Connector on a server in your network and configure Quick Access for the IP ranges your VPN users currently reach. A pilot group of ten to fifteen users switches to Global Secure Access while the existing VPN remains active in parallel.

In the second phase, you identify the five to ten most-used private applications and create per-app configurations. You move user groups to Private Access per application and gradually restrict VPN access. The Global Secure Access dashboards in the Entra portal provide direct visibility into connection errors or unexpectedly blocked traffic.

In the third phase, you enable Entra Internet Access for the pilot group, validate category filtering and logging, and then expand to the rest of the organisation. Once both flows are stable, you set an end date for the VPN infrastructure.

What this changes for your organisation

Global Secure Access is not a replacement that you roll out over a weekend, but the architectural change is substantial. Lateral movement in a successful attack is structurally limited because users never receive broader network access than what the policy allows. IT teams get a single control point for access management instead of separate VPN logs, firewall rules, and Entra signals that need to be correlated independently.

For organisations approaching the end of their VPN hardware's lifespan, or that want to improve network segmentation after a security incident, now is the moment to seriously evaluate Global Secure Access. Want a technical assessment of your current network access or support in the first phase of the rollout? Contact Zarioh.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share