Edit

Configure Explicit Forward Proxy (preview)

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

Important

The Explicit Forward Proxy feature is currently in preview. This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

Prerequisites

Enable Explicit Forward Proxy

You can enable and manage Explicit Forward Proxy by using the Microsoft Entra admin center:

  1. Sign in to the Microsoft Entra admin center.

  2. Go to Global Secure Access > Session management, and then select the Explicit Forward Proxy tab.

  3. Set the Internet Access toggle to Enabled. By default, smart session management is enabled when you enable Explicit Forward Proxy.

  4. Optionally, enable HTTP header session management. For more information, see Configure HTTP header session management.

Screenshot of the tab in the Microsoft Entra admin center for configuring Explicit Forward Proxy.

Important

Explicit Forward Proxy session management relies on IP affinity as one of the session management anchors. We recommend that you configure a Conditional Access policy that restricts the use of Explicit Forward Proxy to networks you trust. For more information, see Explicit Forward Proxy session management and Configure a Conditional Access policy for Explicit Forward Proxy.