QuestionQ340

Design security solutions for applications and data

Your Microsoft Entra tenant contains 800 Microsoft Entra joined devices and 700 users. Each user is assigned a single device. All the devices are onboarded to Global Secure Access.

You use a software as a service (SaaS) application named App1 that is hosted by a third party. Users access App1 over the internet.

You need to ensure that all the devices access App1 through the Global Secure Access client.

What should you use?

  • A a Conditional Access policy
  • B a Quick Access app
  • C a traffic forwarding profile
  • D a security profile
Explanation

Global Secure Access uses traffic forwarding profiles (Microsoft traffic, Private access, and Internet access) to determine which network traffic is routed through the Global Secure Access client. Because App1 is an internet-hosted SaaS application, you must enable and configure the Internet Access traffic forwarding profile so that traffic destined for App1 is tunneled through the Global Secure Access client rather than going directly to the internet. Conditional Access policies can require the Global Secure Access client or a compliant network as a sign-in condition, but they do not control which traffic is actually forwarded through the client; that forwarding behavior is governed by the traffic forwarding profile configuration.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!