| title | Quickstart: Configure per-app access to private resources |
|---|---|
| description | Learn how to configure per-app access to private resources in Global Secure Access. |
| ms.topic | quickstart |
| ms.date | 03/13/2026 |
| ai-usage | ai-assisted |
This quickstart shows you the steps needed to configure per-app access to private resources. For more information about Global Secure Access, see What is Global Secure Access?
Administrators who interact with Global Secure Access features must have the Global Secure Access Administrator role. Some features might also require other roles.
To follow the Zero Trust principle of least privilege, consider using Privileged Identity Management (PIM) to activate just-in-time privileged role assignments.
The product requires licensing. For details, see the licensing section of What is Global Secure Access?. If needed, you can purchase licenses or get trial licenses.
Create specific private apps for granular segmented access to private access resources using Microsoft Entra Private Access.
:::image type="content" source="media/quickstart-per-app-access/private-access-diagram-global-secure-access.png" alt-text="Diagram of the Global Secure Access app traffic flow for private resources." lightbox="media/quickstart-per-app-access/private-access-diagram-global-secure-access.png":::
- Configure a private network connector and connector group.
- Create a private Global Secure Access application.
- Enable the Private Access traffic forwarding profile.
- Install and configure the Global Secure Access Client on end-user devices.
After you complete these steps, users with the Global Secure Access client installed on a Windows device can connect to your private resources through a Global Secure Access app and private network connector.
Optionally: