Skip to main content
Cloud / Azure / Products / Microsoft Entra Internet Access - Identity-Centric Secure Web Gateway

Microsoft Entra Internet Access - Identity-Centric Secure Web Gateway

Microsoft Entra Internet Access: a secure web gateway for SaaS and internet traffic with web content filtering, TLS inspection, and Conditional Access integration.

identity
Pricing Model Per-user monthly license; the Microsoft Entra pricing page lists USD 5.00 per user per month, paid yearly, or included in the Microsoft Entra Suite
Availability Generally available; delivered from Microsoft's Wide Area Network, which per Microsoft spans 70 regions and 190+ network edge locations
Data Sovereignty As a Microsoft Entra service, it can be configured to fall within the scope of the EU Data Boundary
Reliability Per provider; the SLA terms for Microsoft online services apply SLA

Microsoft Entra Internet Access is an identity-centric secure web gateway that governs internet and SaaS access through the same Conditional Access policies used for application access.

What is Microsoft Entra Internet Access?

Microsoft Entra Internet Access provides an identity-centric Secure Web Gateway (SWG) solution for Software as a Service applications and other internet traffic. It protects users, devices, and data from the internet’s wide threat landscape with security controls and visibility through traffic logs.

Together with Microsoft Entra Private Access, Internet Access comprises Microsoft’s Security Service Edge solution; the unifying term for both is Global Secure Access. Both services are generally available per Microsoft.

The key introductory capability is web content filtering. It provides granular access control for web categories and fully qualified domain names. The decisive difference from classic filtering solutions is the point of reference: policies are based on user identity and assigned through Conditional Access, not through network segments.

Core Features

  • Web content filtering: access control by web category and FQDN, effective for remote and in-office endpoints alike
  • Security profiles: group filtering policies and link them to Conditional Access policies
  • Priority-based processing: unique priorities from 100 to 65,000, similar to traditional firewall logic
  • Baseline security profile: acts as a catch-all for all internet traffic routed through the service
  • TLS inspection and threat intelligence: additional security controls in the Internet Access license
  • Data loss prevention and shadow AI discovery: further capabilities per Microsoft’s licensing comparison
  • Traffic acquisition: from the desktop client or from a remote network, such as a branch location

Typical Use Cases

Category-based block lists
Specific web categories are blocked organization-wide, with individual exceptions granted through higher-priority allow rules. Microsoft’s own example: block all news sites but allow msn.com.

Different rules per user group
Because security profiles are linked to Conditional Access policies, different filtering profiles can be enforced for departments or roles.

Securing remote endpoints
Protection applies regardless of whether the device is on the corporate network, because enforcement happens at the cloud edge.

Branch connectivity
Remote networks route traffic for entire locations through the service without installing a client on every device.

Traffic visibility
Detailed traffic logs including enforced policy details, plus dashboards covering users, devices, and destinations. Traffic logs are in preview per Microsoft.

Benefits

  • Identity-aware policies instead of purely network-based rules
  • Enforcement at the cloud edge and therefore independent of device location
  • Universal support for all device platforms
  • Simplified policy management because all policies are based on user identity
  • Managed together with Entra Private Access through the Global Secure Access experience

Integration with innFactory

As an indirect Microsoft CSP partner, innFactory supports you in building an identity-centric web gateway: defining filtering policies, structuring security profiles, linking them to your Conditional Access policies, and connecting branch locations through remote networks.

For how this fits into your overall platform, we describe our approach in our article on Azure Landing Zones.

Contact us for a no-obligation consultation on Security Service Edge with Microsoft Entra.

Typical Use Cases

Securing internet and SaaS access for remote and in-office endpoints
Blocking web categories and individual FQDNs through filtering policies
Identity-based network policies through Conditional Access
Protection against malicious web traffic through threat intelligence
Network controls for AI agents (requires Microsoft Agent 365)

Technical Specifications

0th Web content filtering: granular access control for web categories and fully qualified domain names (FQDNs)
1st Evaluation uses the URL for unencrypted HTTP traffic and Server Name Indication (SNI) for TLS-encrypted HTTPS traffic
2nd Security profiles group filtering policies and are linked to Conditional Access policies
3rd Policy priorities range from 100 (highest priority) to 65,000 (lowest priority)
4th The baseline security profile acts as a catch-all for all internet traffic routed through the service, even without a Conditional Access policy link
5th Additional capabilities per the licensing comparison: TLS inspection, threat intelligence, prompt injection protection, data loss prevention, shadow AI discovery, universal Conditional Access, and universal continuous access evaluation
6th Traffic acquisition from the desktop client or from a remote network, such as a branch location
7th Detailed traffic logs including enforced policy details; traffic logs are in preview per Microsoft

Frequently Asked Questions

Is Microsoft Entra Internet Access generally available?

Yes. Microsoft states in the Global Secure Access documentation: "Microsoft Entra Internet Access, Microsoft Entra Internet Access for Microsoft services, and Microsoft Entra Private Access are now generally available."

What is the key introductory capability?

Microsoft names web content filtering as the key introductory feature for all apps. It provides granular access control for web categories and fully qualified domain names. By explicitly blocking known inappropriate, malicious, or unsafe sites, it protects users and their devices whether they are remote or within the corporate network.

How are policies processed?

Filtering policies are grouped into security profiles, which are linked to Conditional Access policies. Within a security profile, policies are enforced by unique priority numbers, with 100 being the highest priority and 65,000 the lowest. Microsoft recommends spacing of about 100 between priorities. The baseline security profile acts as a catch-all for all internet traffic routed through the service.

How is encrypted traffic evaluated?

When traffic reaches Microsoft's Secure Service Edge, Microsoft Entra Internet Access evaluates unencrypted HTTP traffic using the URL and TLS-encrypted HTTPS traffic using the Server Name Indication (SNI). Microsoft additionally names TLS inspection as an Internet Access license capability, among other things for higher-fidelity web categorization.

How does this differ from Defender for Endpoint or Azure Firewall?

Microsoft itself notes that similar filtering capabilities exist in other products. Microsoft positions the additional value of Entra Internet Access in identity-aware policy integration with Microsoft Entra ID, policy enforcement on the cloud edge, universal support for all device platforms, and security enhancements through TLS inspection. It also simplifies traditional policy management since policies are all based on user identity.

Which license is required?

Per Microsoft, Entra Internet Access capabilities are included in the Microsoft Entra Suite license and available standalone. To use it, users need a Microsoft Entra ID P1 or P2 license. The Entra pricing page lists Entra Internet Access at USD 5.00 per user per month, paid yearly. Network controls for agents additionally require a Microsoft Agent 365 license.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Microsoft Entra Internet Access - Identity-Centric Secure Web Gateway?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation