Event banner
Introducing Microsoft Entra Private Access
Event details
Microsoft Entra Private Access helps secure access to all private apps and resources, for users anywhere, with an identity-centric Zero Trust Network Access (ZTNA) solution. Join us to learn how this solution can help you remove the risk and operational complexity of legacy virtual private networks (VPNs) while boosting user productivity and lowering cost. This event takes what we announced at Reimagine secure access with Microsoft Entra on July 11th and goes further into the technical details you need to get started today!
Once we’ve walked you through some demos and details, we’ll switch to an open Ask Microsoft Anything (AMA) format to answer all your questions about Microsoft Entra Private Access and Internet Access!
This session is part of the Microsoft Entra Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
While you wait, read Identity Management: A Foundation for Zero Trust Security to learn how a modern identity management solution can provide a strong foundation for your overall security strategy.
106 Comments
- Char_CheesmanBronze Contributor
Don't be shy! We’re halfway through the AMA, so keep posting your questions in the Comments.
- En111_Iron Contributor
CA isn't always the answer. A problem is that Intune has a "cache" where the device might be compliant or not for some time that isn't true. Can we do a direct policy that tells Private Access to only let in users with X and Y that is checked on the actual machine, not Intune compliance?
Example: Only allow if on connect time the user is running 3rd party EDR service.exe
- En111_Iron ContributorLess time for CA compliance would indeed be great for all our access use. Thanks for the answers.
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 41:00.
- En111_Iron ContributorExample: Only allow if user is running 3rd party EDR client
- sarthakBrass ContributorAre the App segment rules evaluated on the client or the SSE cloud?
- Ian_Parramore
Microsoft
Traffic Forwarding profiles are managed in the cloud and delivered to the client. The client will evaluate and acquire traffic to send to the cloud service based on these policies. The cloud service will also check the Traffic Forwarding policies as well as the addition of additional policies, controls and checks as configured by the Administration (Tenant Restrictions, Internet Access web filtering policies etc). - Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 39:00.
- RavTinCopper ContributorWill Private access by any chance going to assist in Conditional Access App Control where sometimes if we see delay in page loading/features missing?
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 40:00.
- tpeckmanCopper ContributorWill Microsoft provide default Internet Access profile sets for cataloging websites? (Social media, storage, gambling, gaming, etc). If so, will they be continually updated?
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 44:00.
- Ian_Parramore
Microsoft
Yes, Web Category filtering will be part of the overall Internet Access capability in due course. This is not available in Public Preview yet.
- Richard_HicksCopper ContributorAre there any plans to enable Private Access for machine-level access? Specifically for domain-controller access pre-logon for hybrid Azure AD join scenarios.
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 38:00.
- SamuelRoachIron ContributorOne advantage with this over other solutions, aside from the technical side of things, would probably be cost if it's integrated with M365 E3 & E5. This is often the value proposition with E3/E5.
- SamuelRoachIron ContributorPlus, being part of Entra, no need to integrate Entra Identity with a 3rd party solution.
- FurgieCopper Contributor
If we have public (internet) facing web apps that only corporate Entra ID users access, and we want to MFA users that access the sites, is Entra Private access the best tool or should we look at Entra Internet Access
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 33:00.
- dsghiIron ContributorIf you already host that web application in Azure, and users are already authenticating with Entra ID, you can use conditional access policies to enforce MFA.
- FurgieCopper ContributorI can't see how that can be done? The web app is in Azure and users are authenticating with Entra ID. I want users to only MFA when they access this app and not get MFA'd on a regular basis if I just required them to MFA on any app via CA
- mtittle10Copper ContributorWill Private Access support line-of-sight access to on-premise AD for Self-Service Password Reset at the Windows Login screen?
- Char_CheesmanBronze Contributor
Thanks for participating in today's AMA: Microsoft Entra Internet Access and Microsoft Entra Private Access! For reference, the panel covered this topic at around 43:00.
- RavTinCopper ContributorIs Entra going to be integrated into 365 defender?