Instiq
Chapter 3 · Authentication and Conditional Access·v1.0.0·Updated 6/28/2026·~12 min

What's changed: Created SC-300 Chapter 3 (Domain 2: authentication methods (CBA/TAP/passkeys FIDO2/Authenticator/MFA/SSPR/Windows Hello/password protection/Entra Kerberos); Conditional Access (assignments/controls/session/CAE/authentication context/protected actions/templates/report-only/break-glass exclusion); ID Protection (user/sign-in risk/risky workload id/registration campaigns); Global Secure Access (GSA client/Entra Private Access ZTNA/Entra Internet Access SWG/Internet Access for M365/tenant restrictions)).

3.4Global Secure Access

Key points

Understand deploying Global Secure Access clients and Microsoft Entra Private Access (ZTNA to internal apps) and Microsoft Entra Internet Access (secure web gateway for internet/SaaS and Microsoft 365).

Global Secure Access (GSA) is Microsoft’s Security Service Edge (SSE). Anchored on identity, it securely brokers connectivity to internal apps and the internet/SaaS without relying on a VPN.

3.4.1Entra Private Access (ZTNA)

Microsoft Entra Private Access is ZTNA that connects to internal apps (on-prem/private) without a VPN, identity-based and minimal. Deploy the Global Secure Access client to devices and publish access per app (positioned as a successor/extension to Application Proxy, supporting non-web protocols too). Because Conditional Access applies, you can "enforce explicit verification even for internal apps." For "replace org-wide VPN with identity-based access," use Private Access.

3.4.2Entra Internet Access (SWG)

Microsoft Entra Internet Access inspects/controls users’ internet/SaaS-bound traffic as a secure web gateway. In particular, Internet Access for Microsoft 365 optimizes/protects M365 traffic and enables controls like tenant restrictions ("only allow sign-in to approved org tenants"). Choose between Private Access (internal apps) and Internet Access (internet/SaaS) by destination.

Exam point

Cues: "VPN-less identity-based minimal access to internal apps (non-web too)" = Entra Private Access (ZTNA). "inspect internet/SaaS via secure web gateway" = Entra Internet Access. "optimize M365 traffic + tenant restrictions" = Internet Access for Microsoft 365. Deploy the GSA client to devices.

Warning

Watch the mix-ups: (1) Distinguish Private Access (destination = internal apps) from Internet Access (destination = internet/SaaS). (2) GSA is SSE but Zero Trust only when integrated with Conditional Access. (3) Private Access extends Application Proxy with broader protocol support.

Diagram of GSA client deployment, Entra Private Access (internal-app ZTNA, VPN-less, non-web too), Entra Internet Access (SWG for internet/SaaS), and Internet Access for M365 tenant restrictions.
Choose by destination

3.4.3Section summary

  • Global Secure Access = Microsoft’s SSE; deploy the GSA client to devices
  • Private Access = ZTNA to internal apps (VPN-less, non-web too); Internet Access = SWG for internet/SaaS
  • Internet Access for M365 = M365 optimization + tenant restrictions; choose by destination, integrate with CA

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to replace org-wide VPN with identity-based minimal access to internal apps (on-prem, including non-web protocols). Which is best?

Q2. You want to inspect/control users’ internet/SaaS-bound traffic as a secure web gateway. Which is best?

Q3. You want to prevent employees from signing in to non-approved external org tenants. Which is best?

Q4. What is needed for Global Secure Access to function on endpoints?

Q5. Which correctly distinguishes Private Access from Internet Access?

Check your understandingPractice questions for Chapter 3: Authentication and Conditional Access