Securing internet traffic from devices with identity-aware web filtering and threat protection
Hello Larry Yuan,
Welcome to the Microsoft Q&A and thank you for posting your questions here.
I understand that your GSA traffic forwarding profile user/group assignment shows "temporarily unavailable" for all three default profiles.
This is not the assignment UI itself, but one of the documented assignment eligibility requirements: the traffic profile must be enabled, the user must be directly assigned or directly belong to a supported group, nested groups are not supported, the GSA client must be version 1.7.376.0 or later, and the profile is fetched for the Microsoft Entra user signed into the Windows device, not merely the user visible in the GSA client. - https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-manage-users-groups-assignment
What you can do is to:
- Confirm the required GSA traffic forwarding profile is enabled, because assignment alone does not forward traffic.
- Assign the affected user directly, or assign a supported group where the user is a direct member. Nested groups must not be used.
- Use only supported groups: Security groups or Microsoft 365 groups with
SecurityEnabled=True. - Upgrade the Global Secure Access client to at least 1.7.376.0, because older clients do not receive user/group-assigned traffic forwarding profiles.
- Confirm the Windows signed-in Microsoft Entra user is the same user assigned to the profile, or is a direct member of the assigned group.
- Validate the result from Global Secure Access Client > Advanced Diagnostics > Overview and Forwarding profile, then confirm whether the traffic action is Tunnel, Bypass, or Block from the Traffic tab. - https://learn.microsoft.com/en-us/entra/global-secure-access/troubleshoot-global-secure-access-client-advanced-diagnostics
After correcting the assignment scope, group membership, client version, and signed-in user context, the traffic forwarding profile should be delivered to the client and the expected forwarding rules should appear in Advanced Diagnostics. If the profile still does not appear after all these checks pass, this becomes a backend/service investigation and should be escalated to Microsoft Support with the client diagnostic package, profile ID, tenant ID, affected UPN, device ID, timestamp, destination FQDN/IP, and correlation vector ID. - https://learn.microsoft.com/en-us/entra/global-secure-access/troubleshoot-global-secure-access-client-advanced-diagnostics. Use the above associated official Microsoft resources for more reading and steps.
I hope this is helpful. Please! Do not hesitate to let me know if you have any other questions, steps or clarifications.
Please do not close the thread by upvoting and accepting the answer if any part of it is helpful.