Microsoft Entra Internet Access is an identity-centric secure web gateway that governs internet and SaaS access through the same Conditional Access policies used for application access.
What is Microsoft Entra Internet Access?
Microsoft Entra Internet Access provides an identity-centric Secure Web Gateway (SWG) solution for Software as a Service applications and other internet traffic. It protects users, devices, and data from the internet’s wide threat landscape with security controls and visibility through traffic logs.
Together with Microsoft Entra Private Access, Internet Access comprises Microsoft’s Security Service Edge solution; the unifying term for both is Global Secure Access. Both services are generally available per Microsoft.
The key introductory capability is web content filtering. It provides granular access control for web categories and fully qualified domain names. The decisive difference from classic filtering solutions is the point of reference: policies are based on user identity and assigned through Conditional Access, not through network segments.
Core Features
- Web content filtering: access control by web category and FQDN, effective for remote and in-office endpoints alike
- Security profiles: group filtering policies and link them to Conditional Access policies
- Priority-based processing: unique priorities from 100 to 65,000, similar to traditional firewall logic
- Baseline security profile: acts as a catch-all for all internet traffic routed through the service
- TLS inspection and threat intelligence: additional security controls in the Internet Access license
- Data loss prevention and shadow AI discovery: further capabilities per Microsoft’s licensing comparison
- Traffic acquisition: from the desktop client or from a remote network, such as a branch location
Typical Use Cases
Category-based block lists
Specific web categories are blocked organization-wide, with individual exceptions granted through higher-priority allow rules. Microsoft’s own example: block all news sites but allow msn.com.
Different rules per user group
Because security profiles are linked to Conditional Access policies, different filtering profiles can be enforced for departments or roles.
Securing remote endpoints
Protection applies regardless of whether the device is on the corporate network, because enforcement happens at the cloud edge.
Branch connectivity
Remote networks route traffic for entire locations through the service without installing a client on every device.
Traffic visibility
Detailed traffic logs including enforced policy details, plus dashboards covering users, devices, and destinations. Traffic logs are in preview per Microsoft.
Benefits
- Identity-aware policies instead of purely network-based rules
- Enforcement at the cloud edge and therefore independent of device location
- Universal support for all device platforms
- Simplified policy management because all policies are based on user identity
- Managed together with Entra Private Access through the Global Secure Access experience
Integration with innFactory
As an indirect Microsoft CSP partner, innFactory supports you in building an identity-centric web gateway: defining filtering policies, structuring security profiles, linking them to your Conditional Access policies, and connecting branch locations through remote networks.
For how this fits into your overall platform, we describe our approach in our article on Azure Landing Zones.
Contact us for a no-obligation consultation on Security Service Edge with Microsoft Entra.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
Is Microsoft Entra Internet Access generally available?
Yes. Microsoft states in the Global Secure Access documentation: "Microsoft Entra Internet Access, Microsoft Entra Internet Access for Microsoft services, and Microsoft Entra Private Access are now generally available."
What is the key introductory capability?
Microsoft names web content filtering as the key introductory feature for all apps. It provides granular access control for web categories and fully qualified domain names. By explicitly blocking known inappropriate, malicious, or unsafe sites, it protects users and their devices whether they are remote or within the corporate network.
How are policies processed?
Filtering policies are grouped into security profiles, which are linked to Conditional Access policies. Within a security profile, policies are enforced by unique priority numbers, with 100 being the highest priority and 65,000 the lowest. Microsoft recommends spacing of about 100 between priorities. The baseline security profile acts as a catch-all for all internet traffic routed through the service.
How is encrypted traffic evaluated?
When traffic reaches Microsoft's Secure Service Edge, Microsoft Entra Internet Access evaluates unencrypted HTTP traffic using the URL and TLS-encrypted HTTPS traffic using the Server Name Indication (SNI). Microsoft additionally names TLS inspection as an Internet Access license capability, among other things for higher-fidelity web categorization.
How does this differ from Defender for Endpoint or Azure Firewall?
Microsoft itself notes that similar filtering capabilities exist in other products. Microsoft positions the additional value of Entra Internet Access in identity-aware policy integration with Microsoft Entra ID, policy enforcement on the cloud edge, universal support for all device platforms, and security enhancements through TLS inspection. It also simplifies traditional policy management since policies are all based on user identity.
Which license is required?
Per Microsoft, Entra Internet Access capabilities are included in the Microsoft Entra Suite license and available standalone. To use it, users need a Microsoft Entra ID P1 or P2 license. The Entra pricing page lists Entra Internet Access at USD 5.00 per user per month, paid yearly. Network controls for agents additionally require a Microsoft Agent 365 license.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
