Microsoft Entra Private Access | Replace VPNs for on-premises resources | Global Secure Access

Microsoft Entra Private Access | Replace VPNs for on-premises resources | Global Secure Access

Microsoft Mechanics

7 месяцев назад

31,124 Просмотров

Enable secure access to all your private on-prem and cloud resources, beyond what you can do with traditional VPNs, with Microsoft Entra Private Access, part of Microsoft’s Security Service Edge solution. Private Access takes an identity-centric Zero Trust Network Access approach, and leverages the Conditional Access policy engine to assess risk in real time using identity, device, and application signals, and apply additional network conditions to protect any apps or resources, such as file shares or virtual machines. These capabilities are found under Global Secure Access in the Microsoft Entra admin center.

Ashish Jain, Principal Group PM for Microsoft Entra, shares how Microsoft Entra adds Security Service Edge controls for private connections that you'll find under Global Secure Access in the Microsoft Entra admin center.

► QUICK LINKS:
00:00 - Secure access to all private apps and resources
01:31 - Global Secure Access
02:27 - Set up private app access without using a VPN
03:34 - MFA with Conditional Access policies
05:24 - Connect to infrastructure resources on prem
07:03 - Connect from a mobile device
09:09 - Wrap up

► Link References
Get started at https://entra.microsoft.com

For more information, check out https://aka.ms/SSEPrivateAccessDocs

Check out our playlist at https://aka.ms/SSEMechanics

► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.

• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast

► Keep getting this insider knowledge, join us on social:
• Follow us on Twitter: https://twitter.com/MSFTMechanics
• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics

#ZeroTrust #ConditionalAccess #Cybersecurity #MicrosoftEntra

Тэги:

#security_service_edge #security_service_edge_(sse) #identity_management_and_access_control #Conditional_Access #Microsoft_Entra_Private_Access #microsoft_entra #cybersecurity #microsoft_security #identity_and_access_management #cyber_attack #data_breach #cyber_security #data_protection #VPN #zero_trust_network_access #zero_trust_network_security #multi_factor_authentication #ransomware_attack #private_access_vpn #Global_Secure_Access #global_secure_access #goodbye_vpns
Ссылки и html тэги не поддерживаются


Комментарии:

@Excalibur80
@Excalibur80 - 11.12.2023 10:36

Does Entra Private Access replace the need for Azure Active Directory Domain Services?

Ответить
@saeednouri3586
@saeednouri3586 - 11.12.2023 04:35

What's the recommendation if mobile user is on the same network range as internal? i.e. 192.168.x.x /24 which is quite common in SMB type environments?

Ответить
@davidgorman994
@davidgorman994 - 08.12.2023 23:58

This is really useful. We have tested it here a bit and it could really replace our VPN for some staff. Hopefully it isn't too expensive

Ответить
@flove7808
@flove7808 - 08.12.2023 18:35

Hasn't been released (UDP and private DNS / Kerberos > SMB), yet, right?
Client Version is still 1.6.51.

Ответить
@aRiflip
@aRiflip - 08.12.2023 14:36

Would love to know the pricing of this or if it’s going to be bundled with an existing sub

Ответить
@hotmixer2010
@hotmixer2010 - 08.12.2023 12:41

Zscaler is way better

Ответить
@robertparzefall5949
@robertparzefall5949 - 07.12.2023 23:13

I would like to know how the KDC ticket gets issued, I am having problems with WHfB and accessing on-prem file server resources via KDC, UDP is not implemented, but looking at the clip, it seems to work now. The DC Locator doesn't seem to find the domain controller on the client, not sure what I am missing here. :)

Ответить
@Teramos
@Teramos - 07.12.2023 21:16

The Big Elephant in Room is the Pricing, will it stay at Entra ID P1 or will a separate 10$ per User License be needed. Otherwise absolutely great Product, hope UDP gets implemented soon.

Ответить
@cdfcloud
@cdfcloud - 06.12.2023 23:44

We have all our resources hosted in azure( vm, sql, mongo, container app, azure static webapp, app service, log analytics,etc). How i can set this up for all the engineers in our organization totally 30 engineers most are working remotely, we are having e5 license

Ответить
@ADMEDIA_UK
@ADMEDIA_UK - 06.12.2023 22:18

Surely you need a the vpn between on premise server to azure

Ответить
@laukage
@laukage - 06.12.2023 19:58

Microsoft is really bringing out important features recently! :D

Ответить
@Joshlrrc
@Joshlrrc - 06.12.2023 19:09

Looks great!

Ответить