Quickstart: Configure Quick Access to private resources

Microsoft Entra Private Access provides a secure, zero-trust access solution for accessing internal resources without requiring a VPN. Configure Quick Access and enable the Private Access traffic forwarding profile to specify the sites and apps you want routed through Microsoft Entra Private Access. At this time, the Global Secure Access client must be installed on end-user devices to use Microsoft Entra Private Access, so that step is included in this section.

This quickstart shows you the steps needed to configure Quick Access to private resources. To learn more about Global Secure Access, see What is Global Secure Access?

Prerequisites

Administrators who interact with Global Secure Access features must have the Global Secure Access Administrator role. Some features might also require other roles.

To follow the Zero Trust principle of least privilege, consider using Privileged Identity Management (PIM) to activate just-in-time privileged role assignments.

The product requires licensing. For details, see the licensing section of What is Global Secure Access?. If needed, you can purchase licenses or get trial licenses. To use the Microsoft traffic forwarding profile, a Microsoft 365 E3 license is recommended.

Configure Quick Access to private resources

Set up Quick Access for broader access to your network using Microsoft Entra Private Access.

Diagram of the Quick Access traffic flow for private resources.

  1. Configure a Microsoft Entra private network connector and connector group.
  2. Configure Quick Access to your private resources.
  3. Enable the Private Access traffic forwarding profile.
  4. Install and configure the Global Secure Access Client on end-user devices.

After you complete these four steps, users with the Global Secure Access client installed on a Windows device can connect to private resources, through a Quick Access app and private network connector.

Next step