How has Global Secure Access worked in your environment?

0
1
Asked By MellowBirch42 On

We're currently piloting Microsoft Global Secure Access in an environment with roughly 400 users and 300 devices. So far, Microsoft 365 traffic routing and the Private Access profile for on-premises resources are working well alongside Conditional Access policies. We have three servers configured to route private traffic, and we're also testing the Internet Access profile with TLS inspection to see whether it can replace our current third-party proxy.

For those already using Global Secure Access, how has it been in production? Are there any deployment issues, compatibility problems, configuration tips, or unexpected gotchas we should plan for?

4 Answers

Answered By QuietHarbor19 On

We use the Microsoft 365 and Internet Access profiles at scale, with some Private Access deployments as well. Overall, it has been stable and very low maintenance. Deployment used to require repackaging the client, but installing it through Intune or an RMM tool is much easier now.

A few practical things are worth doing early: disable QUIC in your browsers, configure machines to prefer IPv4, and make good use of the bypass list. Some websites may flag traffic from Azure addresses as suspicious, while geo-sensitive services such as banks may require connections to originate from a local country. Those sites can usually be excluded when necessary.

Also watch for conflicts with an existing proxy or filtering agent. We’ve seen driver and stability problems when both products are active, while the same machines worked normally after switching fully to the Global Secure Access Internet profile.

MellowBirch42 -

Thanks, that’s useful. We already have a browser policy to disable QUIC, and I’ll make sure the IPv4 preference is applied consistently. We’ve also seen a few driver-related blue screens that appear connected to our current proxy, but they stop when the Global Secure Access profile is used.

PracticalOak58 -

There are community-maintained management scripts that handle the QUIC setting, IPv4 preference, and some client options before installation. They can save time compared with building every configuration step from scratch.

Answered By SilverMesa31 On

Private Access has been particularly solid for us. We replaced a large remote desktop environment with it, and the combination of Conditional Access and Intune-managed endpoints has worked very well. So far it has been reliable and largely hands-off.

Answered By CopperLynx7 On

We’ve had a very positive experience. It’s straightforward to configure, especially if you already use Entra ID, Intune, and Conditional Access, and the integration gives you one place to manage identity and access policies. It’s also developing quickly, with new capabilities arriving regularly, and Microsoft support has been surprisingly responsive for a newer product.

The main caveat is that it still doesn’t match every feature offered by the major dedicated networking platforms, so you’ll be responsible for designing and maintaining the solution yourself. For a smaller organization that is already heavily invested in Microsoft, though, the licensing and integration can make it a very compelling option.

MellowBirch42 -

That matches our situation closely. We’re also heavily invested in Microsoft, and the Private Access profile is already looking like a good replacement for our old VPN client. Being able to apply Conditional Access to on-premises resources is a major advantage.

Answered By AmberCircuit6 On

Keep in mind that this is still a relatively young product. It can be excellent for organizations already standardized on Microsoft, but it is not a complete replacement for every mature secure-access platform yet. Test the applications that matter most, especially anything sensitive to source IP, TLS inspection, legacy authentication, or existing proxy drivers, before expanding the rollout.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.