Microsoft Entra Global Secure Access is Microsoft's Security Service Edge (SSE) — the identity-led network access platform that replaces traditional VPNs and adds a Microsoft-traffic-only acceleration layer for M365. For most Australian mid-market organisations, GSA is the most consequential identity product Microsoft has shipped since Conditional Access. The question is not whether to consider it — most tenants will. The question is what it actually replaces, what it doesn't, and when the switch is worth the project cost.
What GSA includes
- Microsoft Traffic — the always-on Microsoft 365 acceleration layer. Routes M365 traffic via Microsoft's network with the GSA client installed. Free for Entra ID P1 tenants in many SKU combinations.
- Internet Access — the secure web gateway. Filtering, web category control, FQDN allow/deny, malware scanning. Paid feature.
- Private Access — the ZTNA component. Replaces traditional VPN by giving users direct, identity-mediated access to internal applications without exposing the corporate network. Paid feature.
What GSA replaces in an AU mid-market tenant
- Cisco AnyConnect, Palo Alto GlobalProtect, Fortinet FortiClient — full-tunnel VPN clients used for remote access to internal apps.
- Cisco Umbrella, Zscaler Internet Access (for the SWG slice) — third-party SWGs deployed independently of the identity stack.
- Zscaler Private Access, Cloudflare Access — competing ZTNA platforms for orgs already running a Zero Trust pattern.
What GSA does not replace
- Site-to-site VPN to AWS/Azure/on-prem datacentres — those are still ExpressRoute, Azure VPN Gateway, or third-party.
- Network firewall — Azure Firewall, Palo Alto VM-Series, FortiGate still own east-west and outbound from datacentre subnets.
- DNS filtering for unmanaged devices — GSA requires the GSA client on the endpoint.
When the switch is worth the project cost
GSA is most worth deploying when: the existing VPN is creaking under modern Microsoft 365 traffic patterns (the all-traffic-through-the-VPN pattern is the worst possible architecture for M365 latency and bandwidth in Australia); the org has Entra ID P1 or P2 already deployed; Conditional Access is in active use and the security team wants Conditional Access policies to extend to network-layer access; the org has any on-prem applications still in use and is paying for VPN concurrent connections.
The 90-day GSA rollout for AU mid-market
- 1Weeks 1-2 — Acquire licences (Internet Access + Private Access if both are needed), assess Microsoft Traffic-only as a quick win; build the inventory of internal apps for Private Access.
- 2Weeks 3-4 — Deploy GSA Connectors in the on-prem network for Private Access to internal apps; deploy the GSA client to a 50-user pilot via Intune.
- 3Weeks 5-6 — Pilot Microsoft Traffic + Private Access for the internal apps with the highest-frequency users (typically finance, HR, line-of-business apps).
- 4Weeks 7-8 — Pilot Internet Access with a representative web filtering policy (block known bad, audit social media, block uncategorised); tune.
- 5Weeks 9-10 — Roll out the GSA client to the broader fleet via Intune; turn off legacy VPN client deployment.
- 6Weeks 11-13 — Decommission legacy VPN concentrator hardware where applicable; transfer remaining users; final security control mapping into Conditional Access.
The AU latency angle
Microsoft Traffic acceleration routes M365 traffic via Microsoft's peering edges. For Australian users accessing M365 endpoints, that means the path is generally Microsoft-to-Microsoft-edge rather than user-via-VPN-to-Sydney-corporate-firewall-then-out-to-Microsoft. The latency difference for Teams calls and SharePoint downloads is meaningful, particularly for users in WA, NT, regional QLD and SA. This alone is often a sufficient business case for Microsoft Traffic-only deployment even before the security argument for Private Access lands.
Try it
Score your GSA readiness
Use the GSA Readiness scorer to see how close your Conditional Access posture is to supporting Microsoft Traffic, Internet Access, and Private Access.
12 questions · 4 domains
Global Secure Access Readiness Assessment
Score your tenant's readiness to consolidate Internet Access and Private Access onto Microsoft Global Secure Access. Pick the option closest to your current state.
Domain 1
Identity foundation
Entra ID tier, MFA posture, and Conditional Access baseline. GSA policies are Conditional Access policies — without the CA foundation, nothing else lands.
What Entra ID tier is the tenant on?
Source: Microsoft Learn: Global Secure Access licensing prerequisites.
What is the tenant's MFA posture?
Source: Microsoft Learn: Conditional Access — Require multi-factor authentication; ASD ISM.
How many Conditional Access policies are running in production?
Source: Microsoft Learn: Conditional Access deployment guide; CIS M365 Benchmark.
Domain 2
Network & connectivity
Current VPN and SWG estate, on-prem app inventory, and the consolidation TCO that determines whether GSA pays back.
What does the current remote access estate look like?
Source: Microsoft Learn: Migrate from VPN to Microsoft Entra Private Access.
What handles internet-bound web traffic from corporate devices today?
Source: Microsoft Learn: Microsoft Entra Internet Access deployment guide.
What proportion of business-critical apps are still on-prem or in private network?
Source: Microsoft Learn: Entra Private Access app configuration.
Domain 3
Endpoint readiness
Intune enrolment coverage, device compliance policies, and OS mix. GSA's agent deploys via Intune; non-managed devices can't run it.
What proportion of corporate devices are enrolled in Intune?
Source: Microsoft Learn: Manage Global Secure Access clients via Microsoft Intune.
Are device compliance policies in use as a Conditional Access gate?
Source: Microsoft Learn: Require compliant device — Conditional Access.
What's the OS mix on managed devices?
Source: Microsoft Learn: Global Secure Access client requirements.
Domain 4
Licensing & operating model
Entra Suite or standalone licensing, monitoring stack, and who runs network security day-to-day.
Is Entra Suite licensing in scope, or just GSA standalone?
Source: Microsoft Learn: Microsoft Entra Suite licensing.
Is Microsoft Sentinel or another SIEM in production?
Source: Microsoft Learn: Global Secure Access logs in Sentinel.
Who runs network security operations day-to-day?
Source: Frontrow Technology — Australian MSP operating-model patterns.
Indicative self-assessment only. For a verified result Frontrow Technology runs an in-tenant Global Secure Access readiness audit against the customer's Entra ID, Intune and network topology.