What's changed: Created SC-300 Chapter 3 (Domain 2: authentication methods (CBA/TAP/passkeys FIDO2/Authenticator/MFA/SSPR/Windows Hello/password protection/Entra Kerberos); Conditional Access (assignments/controls/session/CAE/authentication context/protected actions/templates/report-only/break-glass exclusion); ID Protection (user/sign-in risk/risky workload id/registration campaigns); Global Secure Access (GSA client/Entra Private Access ZTNA/Entra Internet Access SWG/Internet Access for M365/tenant restrictions)).
3.4Global Secure Access
Understand deploying Global Secure Access clients and Microsoft Entra Private Access (ZTNA to internal apps) and Microsoft Entra Internet Access (secure web gateway for internet/SaaS and Microsoft 365).
Global Secure Access (GSA) is Microsoft’s Security Service Edge (SSE). Anchored on identity, it securely brokers connectivity to internal apps and the internet/SaaS without relying on a VPN.
3.4.1Entra Private Access (ZTNA)
Microsoft Entra Private Access is ZTNA that connects to internal apps (on-prem/private) without a VPN, identity-based and minimal. Deploy the Global Secure Access client to devices and publish access per app (positioned as a successor/extension to Application Proxy, supporting non-web protocols too). Because Conditional Access applies, you can "enforce explicit verification even for internal apps." For "replace org-wide VPN with identity-based access," use Private Access.
3.4.2Entra Internet Access (SWG)
Microsoft Entra Internet Access inspects/controls users’ internet/SaaS-bound traffic as a secure web gateway. In particular, Internet Access for Microsoft 365 optimizes/protects M365 traffic and enables controls like tenant restrictions ("only allow sign-in to approved org tenants"). Choose between Private Access (internal apps) and Internet Access (internet/SaaS) by destination.
Cues: "VPN-less identity-based minimal access to internal apps (non-web too)" = Entra Private Access (ZTNA). "inspect internet/SaaS via secure web gateway" = Entra Internet Access. "optimize M365 traffic + tenant restrictions" = Internet Access for Microsoft 365. Deploy the GSA client to devices.
Watch the mix-ups: (1) Distinguish Private Access (destination = internal apps) from Internet Access (destination = internet/SaaS). (2) GSA is SSE but Zero Trust only when integrated with Conditional Access. (3) Private Access extends Application Proxy with broader protocol support.
3.4.3Section summary
- Global Secure Access = Microsoft’s SSE; deploy the GSA client to devices
- Private Access = ZTNA to internal apps (VPN-less, non-web too); Internet Access = SWG for internet/SaaS
- Internet Access for M365 = M365 optimization + tenant restrictions; choose by destination, integrate with CA
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to replace org-wide VPN with identity-based minimal access to internal apps (on-prem, including non-web protocols). Which is best?
Q2. You want to inspect/control users’ internet/SaaS-bound traffic as a secure web gateway. Which is best?
Q3. You want to prevent employees from signing in to non-approved external org tenants. Which is best?
Q4. What is needed for Global Secure Access to function on endpoints?
Q5. Which correctly distinguishes Private Access from Internet Access?

