What Is Microsoft Entra Internet Access? Microsoft's SWG, Explained Honestly
.jpeg)
If your company already lives in Microsoft 365, Microsoft Entra Internet Access looks like the obvious next step. You already pay for Entra ID, your devices are already in Intune, and now Microsoft offers a secure web gateway that plugs straight into Conditional Access. Before you add it to the renewal, it helps to know exactly what the product is, how it moves traffic, and where it stops. If you are still getting your bearings on the category, start with our explainer on what Security Service Edge (SSE) is, because Entra Internet Access is Microsoft's entry into exactly that market.
The short answer
Microsoft Entra Internet Access is Microsoft's identity-centric secure web gateway. Together with Microsoft Entra Private Access, it makes up Global Secure Access, Microsoft's Security Service Edge offering. A Global Secure Access client on the device tunnels traffic to Microsoft's edge, where Microsoft applies web filtering, TLS inspection, threat intelligence, and Conditional Access policy. It is at its best on Microsoft traffic you already license. For the rest of the web it is a cloud proxy, so every request takes a detour through a Microsoft point of presence, and the AI and data controls stack on top of the paid Internet Access profile. dope.security takes a different approach, inspecting traffic on the device and sending it direct.
That is a testable claim. Turn on the Internet Access profile, open a site from a laptop far from the nearest Microsoft edge location, and look at what source IP the site sees and how long each request takes.
What is Microsoft Entra Internet Access?
Microsoft announced general availability of the Microsoft Entra Suite, which includes Entra Internet Access and Entra Private Access, on July 11, 2024. Microsoft positions Global Secure Access as its SSE, and it positions Microsoft Defender for Cloud Apps alongside it as the CASB.
The detail most buyers miss is that Entra Internet Access is really two traffic profiles, licensed differently.
- The Microsoft traffic profile. Included with Entra ID P1 or P2. It carries Microsoft 365 traffic and adds universal tenant restrictions, the compliant network check, source IP restoration for Entra and Graph, and enriched Microsoft 365 logs.
- The Internet Access traffic profile. The paid secure web gateway. Web category filtering, FQDN filtering, TLS inspection, threat intelligence, prompt injection protection, DLP content policies, and Shadow AI discovery all live here, according to Microsoft's own feature table.
Microsoft's public price list shows Entra Internet Access at $5.00 per user per month on an annual commitment, and the Entra Suite at $12.00. Microsoft also notes that Internet Access and Private Access require an Entra ID P1 or P2 license underneath. So the real line item is the gateway plus the identity license it rides on.
How Entra Internet Access works
The architecture is a classic cloud proxy with an identity-aware control plane on top.
- The client. The Global Secure Access client is available for Windows, macOS, iOS, and Android. On mobile it ships inside the Microsoft Defender app. On Windows it captures traffic with a lightweight filter driver rather than a VPN adapter, which Microsoft says helps it coexist with other clients.
- The tunnel. The client forwards traffic that matches a forwarding profile to Microsoft's SSE edge. Microsoft's documentation states that websites then see an edge IP as the source, and source IP restoration only fixes that for Entra and Microsoft Graph.
- The edge. Microsoft's points of presence reference, updated March 2026, lists 44 Global Secure Access service locations across North America, EMEA, APAC, and Latin America, reached over Anycast.
- Branches. Remote networks connect to the edge over IPsec from customer equipment, with Conditional Access not enforced for traffic that arrives without the client.
If the forward-proxy model is new to you, our forward proxy explainer walks through how it behaves. The short version: identity is attached at the edge, but the inspection still happens away from the device.
Does Entra Internet Access add latency?
Yes, for anything routed through the Internet Access profile, because the gateway sits in Microsoft's cloud and the request has to reach it first. A large network helps. It does not remove the trip. Forty-four service locations is a respectable footprint, and it is still a finite set of stopovers between your people and the sites they use all day.
Measured cloud-proxy latency typically runs 40 to 80 milliseconds near a point of presence and 150 to 400 milliseconds when users are far from one, and a modern SaaS page chains dozens of requests before it finishes loading. The math is in the latency math behind cloud proxy SWGs, and the trade-offs of sending everything through a tunnel are covered in split tunnel vs full tunnel.
How much is the detour costing you? Run the Fly-Direct Speed Test to measure your real round-trip latency and compare a cloud PoP detour with inspection on the device. See how dope.security's Fly-Direct Secure Web Gateway removes the stopover, or book a 20-minute demo to see it live.
The takeaway: a bigger edge makes the detour shorter, while on-device inspection removes it.
What Entra Internet Access does well
Credit where it is due. For a Microsoft-standardized shop, some of this is genuinely hard to match.
- Identity in the policy. Conditional Access can require that users reach resources from a compliant network, and the same Entra groups drive web policy. There is no second identity system to sync.
- Tenant restrictions for Microsoft 365. Universal tenant restrictions on the Microsoft profile help stop data from walking out through a personal or foreign Microsoft 365 tenant.
- Low marginal price. If you already own Entra ID P1 or P2, the Microsoft profile costs nothing extra, and the Internet Access add-on lists at $5.00 per user per month.
- A growing AI roadmap. Microsoft documents Shadow AI discovery, Generative AI insights, and prompt injection protection with built-in support for apps such as ChatGPT, Claude, Gemini, DeepSeek, Grok, and Perplexity.
Where Entra Internet Access falls short in 2026
The gaps are specific, and Microsoft documents most of them itself.
Protocol and platform limits
Microsoft's known limitations page for Global Secure Access, updated May 2026, lists several constraints that matter for a mixed, remote workforce.
- No QUIC for Internet Access. UDP on ports 80 and 443 is not tunneled for the Internet Access profile.
- IPv4 only. IPv6 traffic is not acquired and goes direct.
- DNS changes required. DNS over HTTPS, DNS over TLS, and DNSSEC are not supported and must be disabled.
- Virtualization gaps. The client cannot be installed on a machine that hosts virtual machines, and multi-session Azure Virtual Desktop is not supported.
- Fail behavior is a choice. When the cloud connection fails, traffic either goes direct or is blocked, depending on how the rule is hardened.
TLS inspection has documented edges
Microsoft introduced TLS inspection for Entra Internet Access in public preview in May 2025, and everything deeper than a domain decision depends on it. Microsoft's TLS inspection documentation states that it does not negotiate HTTP/2, so sites that require HTTP/2 will not load unless bypassed, and that Encrypted Client Hello is not supported. Certificate-pinned apps need bypasses too, a problem every cloud proxy shares and one we cover in certificate pinning and SSL inspection.
DLP and AI controls stack up
Content policies can allow or block file and text types, or hand content to Microsoft Purview for inline DLP. Microsoft's documentation, updated September 2026, caps Purview scans at 3 MB, performs no OCR, and allows traffic through when Purview cannot finish a scan. Prompt injection protection is text only, applies to JSON-based apps, requires TLS inspection, and requires a Windows device that is Entra joined or hybrid joined. Network controls for AI agents require a separate Microsoft Agent 365 license. Each piece is real. Together they are a stack of prerequisites before you can say "we govern AI."
The hardest AI test is still the same: allow the corporate ChatGPT workspace, block personal ChatGPT on the same domain, and see what is inside the prompt. Universal tenant restrictions cover Microsoft tenants. Other AI tenants are a separate question to prove in a pilot. We walk through the test in how to block personal ChatGPT while keeping the corporate account.
Entra Internet Access vs dope.security: the head-to-head
Both products put a secure web gateway on managed laptops. They put the inspection point in different places. Here is the comparison, line by line.
- Where inspection happens. Entra Internet Access inspects traffic at Microsoft's SSE edge after the Global Secure Access client tunnels it there. dope.security inspects traffic on the device with an on-device SSL inspection proxy.
- Network path. Entra Internet Access sends web traffic to one of 44 documented service locations, and sites see a Microsoft edge IP. dope.security flies direct to the destination, with up to 4x performance over legacy proxy SWGs.
- HTTP/2 under inspection. Microsoft documents that its TLS inspection does not negotiate HTTP/2. The dope.security on-device SSL inspection proxy supports HTTP/2.
- AI tenant control. Entra's universal tenant restrictions focus on Microsoft tenants. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to corporate tenants and blocks personal logins on the same domain.
- DLP for prompts and uploads. Entra hands content to Purview with a 3 MB scan cap and fail-open behavior on incomplete scans. Dopamine DLP intercepts file uploads and AI prompts on the device and classifies them with large language models through zero-retention OpenAI APIs, covering ChatGPT, Claude, Perplexity, Abacus, and Copilot.
- Licensing shape. Entra Internet Access requires Entra ID P1 or P2 underneath, plus Purview and Agent 365 for some AI features. dope.security runs SWG, CASB Neural, and Dopamine DLP under one dope.console.
- Footprint. The dope.security agent is Mac native and Windows and uses less than 100 MB of RAM.
For the wider field, see our guides to secure web gateway vendors in 2026 and Microsoft Purview DLP alternatives. If Microsoft 365 data is the core worry, our Microsoft 365 DLP breakdown covers what E3 and E5 actually include.
Do you need Entra Internet Access, or just the Microsoft profile?
Here is the practical split. The Microsoft traffic profile is included with Entra ID P1 or P2 and does useful, Microsoft-specific things: tenant restrictions, compliant network checks, and better sign-in logs. Many teams can turn that on and stop there for Microsoft 365.
The paid Internet Access profile is where you are buying a general secure web gateway. That is the decision to evaluate against the alternatives, because that is where the detour, the TLS inspection limits, and the AI prerequisites live. If the priority is protecting laptops that work from anywhere, with AI tenant control and prompt-level DLP that does not wait on a cloud edge, a device-first gateway is the cleaner fit. Rollout does not have to be a project either: Outreach Health secured 99% of its devices within one week and cut web access tickets by 70% in 90 days.
The bottom line on Microsoft Entra Internet Access
Put simply: Entra Internet Access earns its place on Microsoft traffic, where identity and tenant restrictions do real work, but for the open web it is a cloud proxy with documented protocol gaps and AI controls that arrive as a stack of prerequisites. If you want web security, AI tenant control, and DLP to run on the laptop and send traffic straight to its destination, that is what dope.security was built to do. Explore the Fly-Direct Secure Web Gateway or book a 20-minute demo and we will run the personal ChatGPT test live.
Frequently Asked Questions
What is the difference between Entra Internet Access and Global Secure Access?
Global Secure Access is the umbrella name for Microsoft's Security Service Edge. It includes Microsoft Entra Internet Access, the secure web gateway, and Microsoft Entra Private Access, the zero trust network access service. Both use the same Global Secure Access client and Microsoft's SSE edge.
How much does Microsoft Entra Internet Access cost?
Microsoft's public price list shows Entra Internet Access at $5.00 per user per month on an annual commitment, and the Entra Suite, which bundles Internet Access and Private Access with other Entra features, at $12.00. Internet Access also requires an Entra ID P1 or P2 license. Inline DLP through Purview and network controls for AI agents carry their own licensing.
Does Entra Internet Access support TLS inspection?
Yes. Microsoft introduced TLS inspection for Entra Internet Access in public preview in May 2025. Its documentation lists limits, including no HTTP/2 negotiation and no support for Encrypted Client Hello, and certificate-pinned apps must be bypassed. dope.security performs SSL inspection on the device with a proxy that supports HTTP/2.
Does Entra Internet Access work on macOS?
Yes. Microsoft lists Global Secure Access clients for Windows, macOS, iOS, and Android, with the mobile clients delivered through the Microsoft Defender app. Some features differ by platform. For example, Microsoft's prompt injection protection requires a Windows device that is Entra joined or hybrid joined.
Can Entra Internet Access block personal ChatGPT accounts?
Entra's universal tenant restrictions are built around Microsoft tenants, and Microsoft documents Shadow AI discovery and prompt injection protection for AI apps. Validate the exact corporate-versus-personal policy you need for non-Microsoft AI tools in a pilot. dope.security Cloud Application Control blocks personal ChatGPT, Claude, Google, and Microsoft 365 logins on the device while allowing corporate tenants.
Can I run dope.security alongside Microsoft Entra?
Yes. dope.security supports single sign-on through OIDC in dope.console and deploys through standard device management such as Intune, so it fits alongside an Entra identity stack. Many teams keep Entra ID for identity and the Microsoft traffic profile for Microsoft 365, and use dope.security as the secure web gateway, AI governance, and DLP layer on the device.



