Providing secure, identity-based access to private apps and resources without traditional VPNs
Global Secure Access (GSA) resources are region-bound, and Quick Access apps can only be assigned to connector groups in the same parent region as the GSA home region. The error “A quick access app cannot be assigned to a group outside parent region” is the expected behavior when the connector group is in a different region (UK South/Europe) than the provisioned GSA home region (Australia Southeast).
The provided context does not describe any supported process or tooling to reprovision or move an existing GSA home region from one geography/region (Australia Southeast) to another (Europe/UK South). It only specifies:
- Quick Access requires a connector group with at least one active private network connector, and the connector version requirement.
- The list of Global Secure Access locations (points of presence) across regions, including UK South and other European locations.
Because no reprovisioning or migration steps for the GSA home region are documented in the context, the only supported guidance from the available information is:
- Ensure connector groups and Quick Access apps are created and used within the same parent region.
- If a different home region is required (for example, to align with UK South/Europe), this must be handled via Azure support so that engineering can review and process the request, similar to other region-related changes that require support and engineering validation.
The documented region access request process indicates that such region-related changes are processed through a support ticket and validated by the Azure Engineering team before access or changes are granted. For a GSA home-region reprovision, open a support request with Microsoft, clearly stating:
- Current GSA home region (Australia Southeast).
- Target region/geography (Europe/UK South).
- Impact (inability to assign Quick Access apps to UK South connector groups).
The support and engineering teams can then confirm whether reprovisioning or tenant-level changes are possible for the specific GSA deployment and perform any required backend operations.
References: