Global Secure access Client disconnected

Chetan Rana 0 Reputation points
2025-08-21T14:40:36.1+00:00

Global Secure access client is disconnected. Checked the health and event viewer.1. Health Check shows error for Tunneling succeeded Private access as false. All other checks are passing.

  1. Event Viewer logs show this error: Global Secure Access client is disconnected from all channels

Internet connection is working fine.

Tried reinstalling, still encountering the same issue.

Microsoft Security | Microsoft Entra | Microsoft Entra Private Access
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Alan La Pietra (CSA) 165 Reputation points Microsoft Employee
    2025-08-25T13:05:46.02+00:00

    Forwarding Profile Misconfiguration

    1. The GSA client relies on a valid forwarding profile to route traffic. If the profile is outdated or malformed, tunneling may fail.
    2. Fix: Delete these registry keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Global Secure Access Client\ForwardingProfile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Global Secure Access Client\ForwardingProfileTimestamp
    3. Then restart the Global Secure Access Policy Retriever Service and the GSA client.

    Break-Glass Mode Enabled

    • If Break-glass mode is active, the client won’t tunnel traffic.
    • Fix: Go to Microsoft Entra Admin Center → Global Secure Access → Connect → Traffic forwarding, and enable at least one traffic profile

    Azure AD Group or Conditional Access Misalignment

    • Users not assigned to the correct Azure AD group or blocked by Conditional Access policies may fail to tunnel.
    • Fix: Ensure affected users are in the correct group and their devices are compliant in Intune. Check Conditional Access policies

    Client Version or OS Settings

    Network Threat Protection Conflicts

    • Some endpoint protection tools (e.g., Sophos) may block GSA traffic.
    • Fix: Temporarily disable Network Threat Protection or whitelist GSA traffic

    Diagnostic Steps

    • Run the GSA Health Check from the system tray icon.
    • Check Event Viewer logs for disconnection errors.
    • Use the Advanced Diagnostics tab to inspect the forwarding profile and tunnel status
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.