QuestionQ24

Design security solutions for infrastructure

Your company has a main office and 10 branch offices. Each branch office has an on-premises file server running Windows Server and multiple devices running either Windows 11 or macOS. The devices are enrolled in Microsoft Intune.

You have a Microsoft Entra tenant.

You need to deploy Global Secure Access to provide web filtering for device traffic to the internet. The solution must ensure that all web traffic from devices in the branch offices is controlled by using Global Secure Access.

What should you do first at each branch office?

  • A Configure an Intune policy to onboard Microsoft Defender for Endpoint to each device.
  • B Configure an IPsec tunnel on the router.
  • C Install the Microsoft Entra private network connector on the file server.
  • D Configure an Intune policy to deploy the Global Secure Access client to each device.
Explanation

Global Secure Access remote network connectivity controls traffic for an entire branch by establishing an IPsec tunnel from the branch router or other on-premises network equipment to a Global Secure Access endpoint. The tunnel can route all internet-bound branch traffic through Global Secure Access for web-content filtering without requiring a client on every device.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!