Your users sign in through Entra but browse through an old proxy. The web rules should know who they are — Microsoft Entra Internet Access sends each device’s web traffic to Microsoft’s edge — Chennai and Pune among its PoPs — where Conditional Access decides what that user may reach, with TLS inspection generally available since November 2025.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Microsoft Entra Internet Access — the secure web gateway in Global Secure Access, sold standalone or in the Entra Suite. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A secure web gateway that takes its rules from who you are — your Entra user, device and risk — not your IP address.
What consolidation actually replaces, dimension by dimension.
| Dimension | An office proxy behind a VPN | Microsoft Entra Internet Access |
|---|---|---|
| Where filtering happens | An on-site proxy remote users reach over VPN | Microsoft’s edge, from Chennai or Pune |
| Who a rule applies to | An IP range or an AD group synced by hand | The Entra user, device and sign-in risk |
| Laptops off the network | Unfiltered until the VPN comes up | Tunnelled by the Global Secure Access client |
| Encrypted traffic | Inspected on a box sized years ago | TLS inspection at the edge, GA since 2025 |
| Price you can read | Appliance quote, support renewals | $5 or ₹415 a user a month, yearly |
| What it is NOT | — | A CASB, a DNS filter or a malware sandbox |
The cheapest test is a trial on ten managed laptops: switch off Secure DNS, apply category rules, and read the traffic logs a week later.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
On Windows and macOS a client acquires TCP web traffic and tunnels it to Microsoft; on iOS and Android the Defender for Endpoint app does the same job.
The user and device sign in to Entra ID; Conditional Access adds the matching security profile to the access token, so every web rule knows who is asking.
Microsoft’s points of presence, Chennai and Pune among them, evaluate TLS, web content, threat intelligence, file and DLP policies in a fixed order, then forward or block.
Branch routers can send traffic over IPsec to the same edge; a baseline profile applies tenant-wide rules there, with internet traffic over branch tunnels in preview.
A client that tunnels web traffic and an edge that reads your Conditional Access token — policy follows the user, not the IP.
Entra Internet Access filters the web by who is browsing, using the same Conditional Access that already guards sign-in.
Rules allow or block web categories and FQDNs, with wildcards, and apply per user or group through Conditional Access.
A threat intelligence policy blocks high-severity domains and URLs from Microsoft and third-party feeds, with an allow list for false alarms.
Source-type rules treat traffic from AI agents apart from users, and HTTP-method rules can stop an agent’s PUT or DELETE calls.
HTTPS is decrypted at Microsoft’s edge with your signed intermediate or a Microsoft-managed certificate, then re-encrypted onward.
Content policies block or allow uploads and downloads by MIME type across all destinations; Purview DLP scanning is in preview.
With TLS inspection on, prompt policies check what users send to generative AI apps and block injection attempts in flight.
The same Conditional Access that gates sign-in delivers the web security profile, so risk, device and group shape browsing rules.
Traffic through the edge feeds a discovery view of cloud and generative AI apps in use, without a separate log connector.
For inline malware and deeper DLP, a Netskope offer activates from the Entra marketplace; it needs TLS inspection and its own licence.
Configuring TLS inspection, a hands-on tour of the Entra Suite, a launch-era deep dive and Microsoft’s 100-second overview. All from Microsoft’s official Microsoft Security and Microsoft Mechanics channels, 2024 to 2026.
A six-minute walkthrough: build the certificate, write a TLS inspection policy and link it to a security profile.
The Entra Suite end to end, showing where Internet Access sits beside Private Access and identity governance.
A 23-minute session from just after GA on policies, Conditional Access and the user experience.
Microsoft’s 100-second introduction, published on the July 2024 general-availability day.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Policies reach the edge inside the user’s access token, so a block can depend on the group, the device’s compliance or the sign-in risk Entra already calculates. A contractor on an unmanaged laptop and a finance user on a compliant one can get different rules for the same site, written in the Conditional Access screens your identity team already runs.
Microsoft lists Internet Access at $5 a user a month on a yearly commitment and prints ₹415 on its Indian pricing page, which few gateways do. For estates already paying for Entra ID P1 through Microsoft 365 E3 or E5, the add-on is the whole cost; for others, P1 at $7 (₹580) comes first, so check what you hold.
Microsoft lists Global Secure Access points of presence in Chennai and Pune, each with remote-network gateways for branches. Web filtering, Private Access and the Microsoft traffic profile all sit in the Entra admin center, and traffic logs can be exported through diagnostic settings to a workspace you place in an Indian Azure region.
There is no Microsoft malware scanner inline yet; that comes from a separately bought Netskope offer. URL-path filtering and Purview DLP are in preview, QUIC and IPv6 are not acquired, and HTTP/2-only sites need a TLS bypass. Traffic logs stay 30 days in the product, and Gartner did not place Microsoft in its 2025 or 2026 SSE Magic Quadrant.
List who has Entra ID P1 through E3, E5 or Business Premium; only they can be covered, and Internet Access is not in E5.
Push the client with Intune, switch off Secure DNS in Chrome and Edge, block UDP 443 and set IPv4 preferred on a pilot group.
Start with category, FQDN and threat-intelligence rules on the baseline profile, then add stricter profiles by group.
Sign the intermediate, deploy the root with Intune, keep the recommended bypass categories and list every pinned app that breaks.
Export traffic logs to an Indian workspace for 180 days, and decide on Defender for Cloud Apps and Netskope ATP.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We already held P1 through E3, so the gateway cost us $5 a head and no new console. Category rules were live in a day.”
“Contractors on personal laptops get a stricter security profile than staff. Conditional Access made that a ten-minute change.”
“Pushing the root certificate with Intune was easy. Finding the pinned mobile apps that broke under inspection took two weeks.”
“Turn off Secure DNS in Chrome and Edge before the pilot, or half the traffic never reaches the client. Nobody told us that.”
“Pune and Chennai PoPs kept page loads normal for our Bengaluru and Hyderabad offices; nobody noticed the switch from the old proxy.”
“Malware scanning needed a separate Netskope deal, and the logs only stay 30 days. Budget both before you sign.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
$5 or ₹415 a user a month, yearly, plus Entra ID P1.
The grid nobody publishes — how deep a gateway inspects traffic vs how tightly its rules follow the user, device and sign-in risk.
Rules ride on Conditional Access tokens; malware scanning via Netskope.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Internet Access, Netskope Next Gen SWG, Cloudflare One Gateway, Cisco Umbrella and Palo Alto Prisma Access — on layer, TLS, roaming, threat and data controls, price, India PoPs and lock-in.
| Dimension | Microsoft Entra Internet Access | Zscaler Internet Access | Netskope Next Gen SWG | Cloudflare One Gateway | Cisco Umbrella | Palo Alto Prisma Access |
|---|---|---|---|---|---|---|
| What it is | Identity-centric SWG | Cloud inline proxy | Instance-aware proxy | DNS + HTTP gateway | DNS layer, then SIG | Cloud-delivered NGFW |
| Enforcement layer | Proxy only | Proxy, no DNS tier | Proxy | DNS and proxy | DNS, proxy at SIG | Proxy plus DNS |
| How traffic arrives | Client; branch preview | Agent, tunnels, PAC | Client and tunnels | WARP, DNS, tunnels | DNS change or client | GlobalProtect, sites |
| TLS inspection | GA Nov 2025, limits | Full, the reference | Full inline | Full at the $7 tier | Selective, SIG only | Full decryption |
| Off-network roaming | Four OS clients | Client Connector | Netskope Client | WARP client | Secure Client module | GlobalProtect |
| Threat protection | Threat intel only | Sandbox by edition | Inline threat engine | AV scan; isolation up | Domains; files at SIG | Advanced threat services |
| Data protection and CASB | No CASB; DLP preview | CASB + DLP editions | CASB heritage, DLP | Both modes; depth extra | API CASB; DLP at SIG | Inline CASB, DLP extra |
| Pricing model | Per user, yearly | Per user, by edition | Per user, platform | Per user, self-serve | Per user, by tier | Quote, users + sites |
| Published entry price | $5 · ₹415/user/mo | ~$6–12 reported | Not published | Free to 50, then $7 | $2.25–6.50/user/mo | Quote only |
| Included vs add-on | P1 needed; CASB apart | Editions add depth | Platform modules | Enterprise for depth | Proxy needs SIG | Services licensed apart |
| India points of presence | Chennai, Pune | 4 Indian cities | 8 Indian data centres | 6 Indian cities | Mumbai, Chennai | 4 Indian locations |
| Analyst standing | Not in the SSE MQ | SSE Leader, 5th year | SSE Leader since 2022 | 2026 SSE Visionary | Evaluated in 2026 | SSE Leader, 4th year |
| Identity and lock-in | Entra identity required | Any SAML identity | Directory-agnostic | Many IdPs, free tier | Point DNS back | Palo Alto policy model |
| Best fit | Entra-first estates | Depth everywhere | Per-app-instance control | Published-price proxy | DNS floor, fast | Palo Alto firewall shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Microsoft Entra Internet Access is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users you protect; IT staff-hour cost). Estimates model the IT time spent on VPN backhaul complaints, proxy exceptions and keeping a separate web filter in step with the directory, at an assumed 1.5 hours per user a year, with 70% of it removed by rules that follow Entra identity. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: Microsoft lists Entra Internet Access at $5 a user a month, paid yearly on an annual commitment, and shows ₹415 a user a month on its Indian pricing page. Every covered user also needs Entra ID P1 ($7, ₹580) or P2 ($10, ₹830), which Microsoft 365 E3, E5 and Business Premium already include. The Entra Suite bundles Internet Access with Private Access and more at $12 (₹1,000). Defender for Cloud Apps and the Netskope malware add-on are bought separately. TechBag maps what you already hold, then invoices in INR with GST.
Best when your users already hold Entra ID P1
Best for a broader rollout
Best for replacing the VPN and the proxy together
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does every user to be covered hold Entra ID P1 or P2? Internet Access sits on top of it, and E5 does not include it.
Are the devices managed, so the client, root certificate and DoH settings can be pushed? Unmanaged ones fall to Defender for Cloud Apps.
Can you switch off Secure DNS in Chrome, Edge and Windows? The client cannot tunnel traffic that resolves over DoH.
Who signs the intermediate, and which pinned or HTTP/2-only apps need bypass rules? Limits: 100 policies, 8,000 destinations.
Is threat intelligence enough, or will you buy Netskope ATP for inline malware scanning, as a separate licence?
Do you need API scans of SaaS data or session controls? Those are Defender for Cloud Apps; Purview DLP inline is in preview.
CERT-In wants 180 days of logs and its FAQ names proxy logs; the product keeps 30 days. Where will the export live?
SEBI CSCRF 4.b and 4.c ask for proxy servers and web filters; for 4.e DNS filtering, which resolver covers non-client devices?
Count the users who already hold Entra ID P1 first, or let a TechBag advisor pilot the client on one group and plan TLS inspection as the certificate project it is.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.