Global Secure Access Internet Access - Browser Authentication not going through GSA tunnel

Techsupport 20 Reputation points
2025-04-28T20:33:59.54+00:00

Hello,

We have Global Secure Access deployed and connected on every user's computer. It is working well for all Microsoft services. We are having issues logging into a 3rd-party browser based app. The app is GReminders which connects to and syncs the users Exchange calendar. Then a client can go in and see the employees calednar to schedule a meeting with them. The user is having is constantly resync their calendar and it is being disconnected from our GSA Conditional Access policy. Upon checking the sign-on logs for the GReminders app in Entra, I can see that the CA policy which blocks access from non-compliant (non GSA networks) is causing the issue.

The GReminders app is registered in Entra and excluded from the CA policy.

I tried to work around this by enabling the Internet Access traffic profile, hoping that when the user logs into GReminders in the browser, it will use the Internet Access profile to mark it as a compliant network through GSA. However, this does not seem to be the case. The sign-in logs of the GReminders app show the login coming from the public IP address of my office, not through GSA. If I look at a sign-on log for Outlook or Sharepoint for example, it shows through GSA: yes. I know the Internet Traffic profile is working properly as I setup web content filtering and that is working. I can also see the traffic logs.

The root issue here is that browser authentication through a 3rd party app is not going through GSA, even with the Internet Traffic Profile enabled.

How can I get GReminders (a browser based 3rd party app) to work go through the GSA compliant network?

Microsoft Entra Internet Access
Microsoft Entra Internet Access
A Microsoft Entra service that provides an identity-centric Secure Web Gateway that protects access to internet, software as a service (SaaS), and Microsoft 365 apps and resources.
56 questions
{count} votes

Accepted answer
  1. Jyotishree Moharana 1,600 Reputation points Microsoft External Staff Moderator
    2025-04-30T15:32:37.6866667+00:00

    That is correct in Internet Access profile normally the bypass policies are allowed and take precedence. In this scenario we would need to check if in the Bypass policies these endpoints are being bypassed or not. Only define the endpoints which you want to be bypassed and whose traffic you don't want to acquire.

    First analyze the traffic when GReminders is accessed, keep note of the endpoints and the ports and then it would be required to cross check if they have defined to be bypassed.

    Whether the traffic will be captured or not depends on what is defined in the default Internet Access policies i.e. in Custom Bypass, Default bypass and default acquire. Default acquire takes lowest precedence after all bypass rules are evaluated.

    Traffic is evaluated from top to bottom, which means it only gets acquired by the Internet traffic profile if it’s not being bypassed in one of the bypass rules.

    The changes made in Internet Access profile should be in harmony with Microsoft traffic profile. When you enable the Internet Access forwarding profile, you should also enable the Microsoft traffic forwarding profile for optimal routing of Microsoft traffic. You enable the Microsoft traffic profile by selecting the profile checkbox on the same page where you enable the Internet Access traffic forwarding profile.

    When a rule is set to Bypass in the Microsoft traffic profile, the Internet Access traffic profile will not acquire this traffic. Even with the Internet Access profile enabled, the bypassed traffic will skip Global Secure Access acquisition and use that client's network routing path to egress to the Internet. Traffic available for acquisition in the Microsoft traffic profile can be only acquired in the Microsoft traffic profile.

    So, if we're requiring any traffic to be acquired in Internet access then it should not be set to bypass in Microsoft traffic profile.

    Manage-microsoft-profile
    Manage-internet-access-profile


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.