Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Center of Excellence for Microsoft

Maximize your Microsoft investment through strategy, security, modernization, adoption, and continuous optimization.

Untitled design (3)

Commercial Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Specialized IT, cybersecurity, and compliance support for schools, BOCES, local governments, and utilities — backed by 40+ years of public-sector experience.  

Untitled design (3)

Locations

We serve clients across the lower 48, with regional concentration in the Northeast, Mid-Atlantic, Southeast, Mountain West, and West.  

Untitled design (3)

The Sourcepass Story

Built and run by technology, security, and managed services people who were tired of how IT gets delivered – and decided to do it differently. 

Untitled design (3)

The Sourcepass Experience

Excellent service, strategic guidance, and technology delivered with innovation – the operating model behind every Sourcepass engagement, across IT, security, Microsoft, and AI. 

Untitled design (3)

 

Why Microsoft Entra Suite is Replacing Legacy VPNs and SWGs

 
Why Microsoft Entra Suite is Replacing Legacy VPNs and SWGs

Your VPN cannot tell the difference between your employee and the attacker who stole their password.

Neither can your web gateway. Neither can the AI tool an employee just pasted a customer list into. Each one sees a fragment of the picture, because identity, network, and SaaS security were built as separate planes that never learned to talk to each other. That gap is where risks live.

It is also where the cost adds up. The VPN authenticates once and trusts everything after, so one phished credential becomes the shortest path to a ransomware incident report. The secure web gateway filters URLs but does not know who the user is. Generative AI traffic slips between all of it, ungoverned and unlogged. Three separate tools, three separate blind spots, and no single place to enforce a decision.

Microsoft Entra Suite is Microsoft's identity and network access bundle that replaces legacy VPNs and secure web gateways with Global Secure Access, a Security Service Edge built on Conditional Access. 

 

What is Global Secure Access?

 

Global Secure Access is the Microsoft Security Service Edge (SSE) offering inside Entra Suite. It is made up of two services that address different access problems.

 

Global Secure Access component

What it replaces or reduces

What it secures

Microsoft Entra Private Access

Legacy VPN tools and broad network access

Private apps, on-premises resources, private-cloud apps, and legacy workloads

Microsoft Entra Internet Access

Standalone secure web gateways for many workloads

Internet traffic, SaaS apps, Microsoft 365 access, and generative AI usage

 

The value is not just that both services sit in the same suite. Both plug into the same Conditional Access policy engine already used across Microsoft 365. That means private app access, SaaS traffic, and AI usage can be governed closer to identity instead of managed across disconnected tools.

 

Why do VPNs Fail at Modern Access Control?

 

VPNs fail at modern access control because they authenticate once and then trust everything that follows. Traditional VPNs operate at the network layer. Once the tunnel is up, the device sits on the corporate subnet and can route to anything the ACLs allow. Authentication happens once, and everything after that is trusted by default.

That design creates four problems that keep showing up in incident reports and budget reviews.

  1. Lateral movement risk. A compromised device inherits the same broad network reach as the legitimate user. Stolen credentials from a phishing attempt become a master key to the internal network, which is a standard step in most ransomware playbooks.
  2. Legacy protocols with no MFA. RDP, SSH, SMB, and older line-of-business clients were never designed to enforce MFA at the app layer.
  3. Ongoing appliance overhead. Concentrators, licenses, patch cycles, and a steady stream of VPN zero-days on the perimeter appliances themselves.
  4. Rough user experience. Full-tunnel routing and slow international performance.

This is why the VPN replacement conversation has become harder to avoid for many Microsoft 365 environments.

 

How Entra Private Access Replaces the VPN

 

Private Access uses a lightweight connector installed inside your network. That connector dials outbound to the Microsoft cloud, so no inbound firewall ports are required, and no public IP is exposed for the private resource.

The Global Secure Access client routes only the traffic you scope to that connector. A browser session works too, for clientless scenarios.

Capabilities worth knowing before a pilot:

  • Per-app segmentation for web apps and for TCP and UDP protocols including RDP, SSH, and legacy client-server apps.
  • MFA and device compliance on every connection, including on legacy apps that could never enforce that level of security natively.
  • Traffic routed through the Microsoft global backbone, which often outperforms the public internet for users traveling or working from constrained networks.

One deployment note that catches teams off guard: the Windows Global Secure Access client requires the endpoint to be Entra-joined or hybrid-joined. Audit your identity posture on endpoints before you scope the pilot.

 

VPN vs Entra Private Access

 

 

Dimension

Traditional VPN

Entra Private Access

Access model

Broad network access after tunnel up

Per-app, per-session, identity-gated

Authentication

Once, at connect

Continuous, every request

MFA on legacy protocols

Rarely feasible

Enforced through Conditional Access

Firewall exposure

Inbound ports for concentrators

Outbound-only connectors

Lateral movement risk

High if credential is stolen

Contained to scoped apps

Policy plane

Separate from identity and SaaS

Unified with Conditional Access

Client experience

Full tunnel, reconnect loops

Split tunnel, transparent client

 

How Entra Internet Access Secures SaaS and AI Traffic

 

The other half of Global Secure Access handles outbound traffic to the internet, SaaS apps, and AI services. It is positioned as a direct replacement for standalone secure web gateways such as Zscaler or Netskope for many workloads.

At the base layer, it does what any modern SWG does: web content filtering by category, URL, and fully qualified domain name, threat intelligence blocking, and detailed traffic logs.

What sets Internet Access apart in the Entra Suite is the AI gateway layer that Microsoft added in the last cycle of updates. It provides:

  • Shadow AI discovery. Network-level visibility into unsanctioned generative AI apps employees and agents are reaching.
  • Unauthorized AI app blocking. Control over which generative AI tools employees are allowed to use.
  • Data loss controls for prompts. Filtering for what users are permitted to upload into approved tools.
  • AI prompt shielding. Protection against prompt-based attacks at the network layer.
  • AI interaction logging and auditing. Evidence for compliance, investigation, or policy review.

Private Access narrows access to internal resources. Internet Access extends the same identity-aware control model to the internet, SaaS apps, and AI traffic. Because policies are attached to the user through Conditional Access, the same allow, warn, or block decision follows the person across device, network, and location.

 

How does Conditional Access Control Global Secure Access?

 

Conditional Access is the single policy engine behind both halves of Global Secure Access. That is the reason the suite feels different from bolting a SASE product onto Entra ID. Private app access, SaaS traffic, and AI usage are all governed by the same policies you already use across Microsoft 365, evaluated continuously rather than once at connect.

 

What does Entra Suite Cost Compared to your Current Tools?

 

For teams weighing Entra Suite against renewing a SASE contract, the decision usually comes down to cost. Instead of looking at Entra Suite as another add-on, compare it against the tools already in the stack.

 

Current tool category

Common cost or complexity driver

Entra Suite capability to compare

VPN concentrators and licenses

Hardware refresh, client licensing, patching, and internet-facing appliance risk

Entra Private Access

Standalone secure web gateway

Separate policy console, SaaS filtering rules, zero-day vulnerabilities and per-user seat costs

Entra Internet Access

 

At $12 per user per month, the bundle comes in below what a standalone VPN and secure web gateway typically cost on their own, before you count the other tools it can displace. If your current stack is already Microsoft-heavy, Entra Suite may reduce overlap across VPN, SWG, and AI traffic controls.

 

How Much does Entra Suite Cost?

 

Global Secure Access can be licensed in a few different ways, depending on whether the customer wants the full Entra bundle or only one access component.

The main paths are:

  • Microsoft Entra Suite, listed at $12 per user per month as an add-on to a qualifying Entra ID P1 base

  • Microsoft 365 E7, listed at $99 per user per month, which includes Entra Suite as part of the broader E7 bundle

  • Entra Private Access standalone, for customers that only want the VPN replacement/ZTNA component for private apps

  • Entra Internet Access standalone, for customers that only want the secure web and AI gateway component for internet, SaaS, and AI traffic

  • Separate component purchase/deployment, where Private Access and Internet Access are licensed individually instead of adopting the full suite.

Entra ID P1 is still the required base license, so Business Premium, Microsoft 365 E3, Microsoft 365 E5, and Microsoft 365 E7 already satisfy that prerequisite, while Business Basic and Business Standard typically require a P1 add-on first.

Microsoft Entra Suite and Global Secure Access FAQ

Is Entra Suite the Right VPN Replacement for your Stack?

 

Legacy VPNs solve connectivity, but they do not solve modern access control. Microsoft Entra Suite uses Global Secure Access to narrow private app access, apply Conditional Access to internet and SaaS traffic, and add visibility into AI use.

For Microsoft 365 environments, the decision comes down to whether separate VPN, SWG, and PIM tools still justify their cost and complexity when the same controls can be managed closer to identity. If you want a second set of eyes on where Entra Suite fits your current stack, or you have questions about licensing and rollout, reach out to us and we can walk through it with you.

 

 

Have questions about your Microsoft licensing?