Skip to main content
Cloud / Azure / Products / Microsoft Entra Private Access - Zero Trust Network Access Instead of VPN

Microsoft Entra Private Access - Zero Trust Network Access Instead of VPN

Microsoft Entra Private Access: identity-centric ZTNA for private corporate applications, with Quick Access, per-app access, and Conditional Access.

identity
Pricing Model Per-user monthly license; the Microsoft Entra pricing page lists USD 5.00 per user per month, paid yearly, or included in the Microsoft Entra Suite
Availability Generally available; delivered from Microsoft's Wide Area Network, which per Microsoft spans 70 regions and 190+ network edge locations
Data Sovereignty As a Microsoft Entra service, it can be configured to fall within the scope of the EU Data Boundary
Reliability Per provider; the SLA terms for Microsoft online services apply SLA

Microsoft Entra Private Access delivers access to internal applications without a VPN, governed by identity and Conditional Access rather than network membership.

What is Microsoft Entra Private Access?

With Microsoft Entra Private Access you specify the fully qualified domain names (FQDNs) and IP addresses you consider private or internal, and manage how your organization accesses them. Remote workers no longer need a VPN if they have the Global Secure Access Client installed; the client connects them quietly and seamlessly.

Together with Microsoft Entra Internet Access, Private Access comprises Microsoft’s Security Service Edge (SSE) solution; Global Secure Access is the unifying term for both. Both services are generally available per Microsoft and are delivered from Microsoft’s Wide Area Network, which Microsoft describes as spanning 70 regions and 190+ network edge locations.

There are two ways to configure private resources: Quick Access as the primary group of always-tunneled destinations, and the Global Secure Access app for granular per-app access.

Core Features

  • Quick Access: Zero Trust-based access to a range of IP addresses and FQDNs without a legacy VPN
  • Per-app access: granular protection of individual private resources for TCP and UDP applications
  • Conditional Access: assign users and groups to the application and control access through policies
  • Private network connector: brokers the connection between the service and the internal resource
  • App discovery: identifies the private applications in use
  • Private DNS and single sign-on: private name resolution and single sign-on across all private apps
  • Modernized legacy authentication: through deep Conditional Access integration

Typical Use Cases

VPN replacement
The most common starting point: instead of placing users on the network, access is granted per application and identity.

Different policies for subsets of users
When one group of users must meet stricter requirements, a dedicated Global Secure Access app captures that cleanly.

Time-limited access
Resources that should only be reachable for a defined period can be configured as their own application and revoked afterwards.

Hybrid and multicloud access
Remote users reach private apps across hybrid and multicloud environments, private networks, and datacenters from any device and network.

Legacy applications without modern authentication
Conditional Access integration brings older applications into a Zero Trust model as well.

Benefits

  • Access by identity rather than network location
  • More granular control than a classic VPN through per-app adaptive access
  • A one-time configuration instead of ongoing VPN profile maintenance
  • A seamless end-user experience through the Global Secure Access Client
  • Can be deployed side by side with existing non-Microsoft SSE solutions

Integration with innFactory

As an indirect Microsoft CSP partner, innFactory supports you in replacing existing VPN infrastructure: inventorying internal applications, drawing the line between Quick Access and per-app access, designing Conditional Access policies, and rolling out the client.

For the underlying platform and its network architecture, we describe our approach in our article on Azure Landing Zones.

Contact us for a no-obligation consultation on Zero Trust Network Access with Microsoft Entra.

Typical Use Cases

Replacing a legacy VPN for access to internal applications
Per-app access to TCP and UDP applications with dedicated Conditional Access policies
Remote worker access to private apps across hybrid and multicloud environments
Modernizing authentication for legacy applications
Time-limited access to individual internal resources

Technical Specifications

0th Quick Access: the primary group of FQDNs, IP addresses, and IP ranges that are always tunneled through the service
1st Global Secure Access app: granular per-app access to a subset of private resources
2nd Both options create an enterprise application that acts as a container for the resources being secured
3rd The Microsoft Entra private network connector brokers the connection between the service and the internal resource
4th Users and groups are assigned to the app, and access is controlled through Conditional Access policies
5th Per-app access for TCP and UDP applications, app discovery, private DNS resolution, and single sign-on across all private apps
6th Builds on the capabilities of Microsoft Entra application proxy and extends access to any private resource, port, and protocol
7th Per Microsoft, marketplace availability and multicloud support for the private network connector are in preview

Frequently Asked Questions

Is Microsoft Entra Private Access generally available?

Yes. Microsoft states in the Global Secure Access documentation: "Microsoft Entra Internet Access, Microsoft Entra Internet Access for Microsoft services, and Microsoft Entra Private Access are now generally available."

What is the difference between Quick Access and per-app access?

Quick Access is the primary group of FQDNs, IP addresses, and IP ranges you always want to tunnel through the service. A Global Secure Access app, by contrast, provides granular per-app access to a subset of private resources. Microsoft names three typical reasons for the per-app approach: different Conditional Access policies for a subset of users, individual resources that need their own access policies, and access limited to a specific time frame.

Does Private Access replace a VPN?

Microsoft describes Private Access explicitly as a way to replace the VPN: remote workers don't need a VPN if they have the Global Secure Access Client installed. The service also offers per-app adaptive access based on Conditional Access policies, giving more granular security than a VPN.

Which license is required?

Per Microsoft, Entra Private Access capabilities are included in the Microsoft Entra Suite license and available standalone. To use it, users need a Microsoft Entra ID P1 or P2 license. The Entra pricing page lists Entra Private Access at USD 5.00 per user per month, paid yearly.

How is the connection to the internal resource established?

Through the Microsoft Entra private network connector. Each application, both Quick Access and a per-app application, has its own connector that brokers the connection between the service and the internal resource. Users and groups are assigned to the application, and access is controlled through Conditional Access.

Which protocols are supported?

Microsoft names per-app access for Transmission Control Protocol (TCP) and User Datagram Protocol (UDP) applications. Private Access builds on the capabilities of Microsoft Entra application proxy and extends access to any private resource, port, and protocol.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Microsoft Entra Private Access - Zero Trust Network Access Instead of VPN?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation