Event banner

Ask Microsoft Anything: Security Service Edge (SSE)

Event Ended
Wednesday, Aug 14, 2024, 09:00 AM PDT
Online

Event details

Ask Microsoft Anything about securing access to any app or resource, from anywhere. Our panel of experts will answer you questions about Microsoft Entra Internet Access, Microsoft Entra Private Access, and how these products work together as part of Microsoft's Security Service Edge solution.

 

This session is part of the Microsoft Entra Suite Tech Accelerator


Get a head start

Watch Zero Trust in the Age of AI to learn how to simplify your Zero Trust strategy with the latest end-to-end security innovations.

Heather_Poulsen
Updated May 14, 2025

59 Comments

  • danjb's avatar
    danjb
    Brass Contributor
    Will there be the ability to select the regions that we can assign to users? I have a lot of customers with staff in Philippines the need to provide a node/gateway there for SSE [since hopping via Singapore adds significant latency to their connection]
    • tdetzner's avatar
      tdetzner
      Icon for Microsoft rankMicrosoft
      That's great feedback, thank you for sharing. We are looking into these capabilities for future updates. Are you looking mainly towards private access based apps or internet based apps for these controls?
      • danjb's avatar
        danjb
        Brass Contributor
        The organizations I am thinking of are mainly using internet based [SaaS apps] including M365 and 3rd party SaaS As you may be aware there is a massive and growing workforce based in Philippines that is working for overseas companies and they primarily use applications that are not based in Philippines. [Since the companies are not based there]. They also tend to use a lot of latency sensitive tools like Teams and VoIP So having a local node is key for low latency access into Microsofts global WAN network.
    • NeilB965's avatar
      NeilB965
      Occasional Reader
      Or, more clearly, will there be a GSA client for WinonARM, or are we going to wait for the fully integrated version?
      • tdetzner's avatar
        tdetzner
        Icon for Microsoft rankMicrosoft
        The Global Secure Access client on ARM64 architecture isn't yet supported. However, ARM64 is on the roadmap.
  • TrevorRusher's avatar
    TrevorRusher
    Icon for Community Manager rankCommunity Manager

    Welcome! The Security Service Edge (SSE) AMA will start at 9:00 a.m. Pacific Time. What questions do you have for our experts? Post them early and we’ll use them to kick off the hour!

  • If M365/Entra services go down, similar to last week, how will that impact end users using Internet Access or Private Access?
    • Anupma_Sharma's avatar
      Anupma_Sharma
      Former Employee
      We have designed the product from day 1 with breakglass capabilities during contingencies. These capabilities can be dialed in manually during outages to ensure business continuity. Reference: https://learn.microsoft.com/en-us/entra/global-secure-access/scripts/powershell-break-glass. Soon we will be releasing more automated provisions that the traffic can be automatically bypassed if the service is not reachable (based on admin preference).
  • DMoenks's avatar
    DMoenks
    Copper Contributor
    On a high level, how is Entra Private Access different from Entra Application Proxy, both regarding functionality and licensing? Are there plans to deprecate the latter in favor of the former?
    • Abdi_Saeedabadi's avatar
      Abdi_Saeedabadi
      Icon for Microsoft rankMicrosoft
      Private Access significantly expands Entra ID Application Proxy capabilities in Microsoft Entra to a complete ZTNA solution that shares the same connectors but offers so much more, it helps you simplify and secure access to any private resource on any port, and protocol. You can apply policies that enable secure, segmented, and granular access to all your private applications in your corporate network, on-premises, or in the cloud. If you are already using Application Proxy, you can seamlessly transition to Private Access – all existing use-cases and access to existing private web applications would continue to work with no disruption.
  • NeilB965's avatar
    NeilB965
    Occasional Reader
    We use defender for endpoint (along with all the MS related products). Is it recommeneded to use GSA - Entra Internet Access when we already have defender smartscreen accomplishing much of the blocked categories?
  • NeilB965's avatar
    NeilB965
    Occasional Reader
    Any hints on when the ios GSA-enabled defender application will be Generally Available?
    • tdetzner's avatar
      tdetzner
      Icon for Microsoft rankMicrosoft
      We are working on it and hope to have it in public preview soon.
  • NeilB965's avatar
    NeilB965
    Occasional Reader
    For entra Private Access: how do we setup the network security and access for cloud hosted resources, in the case of a severless resource/s (like a sql db)
    • NeilB965's avatar
      NeilB965
      Occasional Reader
      or at least some guidance on best practices on setting up these resources' network security settings to allow for Entra Private Access traffic ?
      • Sumeet Mittal's avatar
        Sumeet Mittal
        Icon for Microsoft rankMicrosoft
        Network security and access for clous hosted resources can be configured in the similar manner through setting up an on cloud Private Network Connector in front of your cloud apps. For ease you can also deploy the connector through Azure or AWS Marketplaces.
  • We hope you're looking forward to this AMA! Feel free to post your questions early here in the Comments—and please post one Comment per question to make it easy for our product team members to see them all. Thank you!

    • NeilB965's avatar
      NeilB965
      Occasional Reader
      For entra Private Access: how do we setup the network security and access for cloud hosted resources, in the case of a severless resource/s (like a sql db)
    • NeilB965's avatar
      NeilB965
      Occasional Reader
      Any hints on when the ios GSA-enabled defender application will be Generally Available?
    • NeilB965's avatar
      NeilB965
      Occasional Reader
      We use defender for endpoint (along with all the MS related products). Is it recommeneded to use GSA - Entra Internet Access when we already have defender smartscreen accomplishing much of the blocked categories?
Date and Time
Aug 14, 20249:00 AM - 9:30 AM PDT