Global Secure Access (GSA) helps us better protect client data, reduce security risks, and respond more quickly to potential threats. Learn more about what it is and why we use it below.
Table of Contents
As hybrid work environments become more common, businesses need a secure way for employees to connect and access apps, data, and tools from anywhere, when they are not in the office.
Security Service Edge (SSE) helps employees gain access to all apps and data from anywhere securely. Microsoft's SSE, Global Secure Access, protects internet and private app access using Zero Trust security.
To further strengthen our security posture, we have implemented Microsoft Global Secure Access (GSA). This cloud-based security platform helps ensure that employees can securely access the applications and data they need, regardless of location.
Microsoft Global Secure Access (GSA) is a cloud-based security solution that helps employees securely access the applications and data they need from any location. Built on Zero Trust principles, GSA verifies a user's identity and security status before granting access and continuously evaluates access throughout a session.
Microsoft Entra ID = verifies who the user is.
Global Secure Access (GSA) = controls how and where that user can access apps and data.
Microsoft Entra Internet Access = secures internet and SaaS application access.
Microsoft Entra Private Access = secures access to private/internal applications without a VPN.
Traditional VPNs have long enabled secure remote access to your data by connecting users to a company's network from locations such as home offices. With a traditional VPN, once you’re connected, you can access the applications and resources you have permission to use on that network.
Microsoft Global Secure Access takes a different approach. Rather than connecting users to the corporate network first, it connects them directly to the approved applications and resources they need after it verifies a user's identity. The goal is to give users secure access to the applications and data they need without requiring full access to the company network.
This approach limits unnecessary network access, helping ensure users can reach what they need without exposing more of the network than necessary.
VPNs often grant broad network access once a user is connected.
GSA verifies the user's identity, device health, location, and risk level every time access is requested.
Employees can securely access company resources from anywhere without needing to connect to a VPN.
If a user's account is compromised, attackers cannot freely move throughout the network.
GSA was designed specifically to secure cloud and internet-based access, whereas VPNs were built primarily for accessing traditional on-premises networks.
Want to learn more information about this change? Get in touch with your vCIO.