Global Secure Access - Cannot assign non-Europe connector group to Enterprise Apps

Darin Mirchev 40 Reputation points

Hello Team,

I would appreciate your help on this, as we cannot explain this behavior of Global Secure Access connector group issue.

We have deployed a VM Proxy Connector in the US region and have created a connector group that is assigned to the North America region, respectively.
However, when we want to assign this connector group to any Enterprise Application, it just does not appear in the dropdown menu. The only connector groups that appear are the Europe region ones that we had already created in the past and are working as expected.
If we change the region of the new connector group to Europe, that is supposedly needed to be in NA region, it instantly appears in the dropdown menu of the Enterprise Applications. This means that for some reason we can only assign European region connector groups.

Please explain if this is due to the state being in Preview and maybe this functionality is not yet developed properly, or is it by design like that, because it makes no sense.
The idea of the connector group regions is to select the region which is closest to the Enterprise Apps that we want to provided the users access to, in order to reduce the latency as much as possible. I don't see the reason why non-European regions would not appear at all in the dropdown menu of the selection.

Thanks in advance!

Microsoft Entra Private Access
Microsoft Entra Private Access
Microsoft Entra Private Access provides secure and deep identity-aware, Zero Trust network access to all private apps and resources.
57 questions
{count} votes

Accepted answer
  1. Akshay-MSFT 17,656 Reputation points Microsoft Employee

    @Darin Mirchev

    Thank you for posting your query on Microsoft Q&A, from above description I could understand that you have created multiple connector for each location but unable to select any apart from connector group configured for Europe region.

    Please do correct me if this is not the case by responding in the comments section.

    I was able to research on this behavior and found as per connector groups doc:

    Microsoft Entra Private Access does not support multi-geo connectors. The cloud service instances for your connector are chosen in the same region as your Microsoft Entra tenant (or the closest region to it) even if you have connectors installed in regions different from your default region. User's image


    Akshay Kaushik

    Please "Accept the answer(Yes)" and "share your feedback ". This will help us and others in the community as well.

0 additional answers

Sort by: Most helpful