Quickstart: Install the Windows client to acquire Microsoft traffic

Microsoft Entra Internet Access isolates the traffic for Microsoft applications and resources, such as Exchange Online and SharePoint Online. Users can access these resources by connecting to the Global Secure Access client or through a remote network, such as in a branch office location.

This quickstart shows you the steps needed to install the client and start acquiring Microsoft traffic. To learn more about Global Secure Access, see What is Global Secure Access?

Prerequisites

Administrators who interact with Global Secure Access features must have the Global Secure Access Administrator role. Some features might also require other roles.

To follow the Zero Trust principle of least privilege, consider using Privileged Identity Management (PIM) to activate just-in-time privileged role assignments.

The product requires licensing. For details, see the licensing section of What is Global Secure Access?. If needed, you can purchase licenses or get trial licenses. To use the Microsoft traffic forwarding profile, a Microsoft 365 E3 license is recommended.

Install the client to acquire Microsoft traffic

Diagram of the basic Microsoft Entra Internet Access traffic flow.

  1. Enable the Microsoft traffic forwarding profile.
  2. Install and configure the Global Secure Access Client on end-user devices.
  3. Enable universal tenant restrictions.
  4. Enable enhanced Global Secure Access signaling and Conditional Access.

After you complete these four steps, users with the Global Secure Access client installed on their Windows device can securely access Microsoft resources from anywhere. Conditional Access policy requires users to use the Global Secure Access client or a configured remote network, when they access Exchange Online and SharePoint Online.

Next step