GSA - Private DNS settings not showing up in Enterprise Application settings

David Baxter 25 Reputation points
2025-04-30T20:04:37+00:00

Setting up Private Access. Installed connectors successfully on Domain servers. However, when creating an Enterprise application (Not Quick Access; I want granular control in Private Access), I am unable to enable Private DNS or configure that setting, as the tab is missing. Then, when I save the application using the FQDN of the resource, I get an error message: "Application could not be saved due to errors. Please review and make the appropriate changes."

I have found documentation saying to use the aka.ms/vpnreplacement link, but the Private DNS tab only appears if I'm setting up Quick Access. Thing is, I don't want to set up quick access, but specific access to specific domain resources that I can configure Conditional Access policies for.

What am I missing?User's image

Microsoft Security | Microsoft Entra | Microsoft Entra Private Access
0 comments No comments
{count} vote

Accepted answer
  1. Michael Morten Sonne 680 Reputation points MVP
    2025-05-01T13:02:56.4566667+00:00

    Hi,

    As per. documentation, this is by design for now: https://learn.microsoft.com/en-us/entra/global-secure-access/concept-private-name-resolution?wt.mc_id=MVP_353010

    "When a DNS suffix is configured in Quick Access, all DNS queries for a fully qualified domain name (FQDN) that ends with the matching suffixes are resolved by Private DNS, including those used to define Enterprise Apps (the way you will use it)."


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.