Why Microsoft Entra Suite is Replacing Legacy VPNs and SWGs
Oct 01, 2026
Nicole Walker
Cloud Security
|
Licensing & Cost Control
|
Microsoft Solutions
|
Microsoft 365
|
Cybersecurity
|
Sourcepass MCOE
6 min read
Your VPN cannot tell the difference between your employee and the attacker who stole their password.
Neither can your web gateway. Neither can the AI tool an employee just pasted a customer list into. Each one sees a fragment of the picture, because identity, network, and SaaS security were built as separate planes that never learned to talk to each other. That gap is where risks live.
It is also where the cost adds up. The VPN authenticates once and trusts everything after, so one phished credential becomes the shortest path to a ransomware incident report. The secure web gateway filters URLs but does not know who the user is. Generative AI traffic slips between all of it, ungoverned and unlogged. Three separate tools, three separate blind spots, and no single place to enforce a decision.
Microsoft Entra Suite is Microsoft's identity and network access bundle that replaces legacy VPNs and secure web gateways with Global Secure Access, a Security Service Edge built on Conditional Access.
What is Global Secure Access?
Global Secure Access is the Microsoft Security Service Edge (SSE) offering inside Entra Suite. It is made up of two services that address different access problems.
|
Global Secure Access component |
What it replaces or reduces |
What it secures |
|---|---|---|
|
Microsoft Entra Private Access |
Legacy VPN tools and broad network access |
Private apps, on-premises resources, private-cloud apps, and legacy workloads |
|
Microsoft Entra Internet Access |
Standalone secure web gateways for many workloads |
Internet traffic, SaaS apps, Microsoft 365 access, and generative AI usage |
The value is not just that both services sit in the same suite. Both plug into the same Conditional Access policy engine already used across Microsoft 365. That means private app access, SaaS traffic, and AI usage can be governed closer to identity instead of managed across disconnected tools.
Why do VPNs Fail at Modern Access Control?
VPNs fail at modern access control because they authenticate once and then trust everything that follows. Traditional VPNs operate at the network layer. Once the tunnel is up, the device sits on the corporate subnet and can route to anything the ACLs allow. Authentication happens once, and everything after that is trusted by default.
That design creates four problems that keep showing up in incident reports and budget reviews.
- Lateral movement risk. A compromised device inherits the same broad network reach as the legitimate user. Stolen credentials from a phishing attempt become a master key to the internal network, which is a standard step in most ransomware playbooks.
- Legacy protocols with no MFA. RDP, SSH, SMB, and older line-of-business clients were never designed to enforce MFA at the app layer.
- Ongoing appliance overhead. Concentrators, licenses, patch cycles, and a steady stream of VPN zero-days on the perimeter appliances themselves.
- Rough user experience. Full-tunnel routing and slow international performance.
This is why the VPN replacement conversation has become harder to avoid for many Microsoft 365 environments.
How Entra Private Access Replaces the VPN
Private Access uses a lightweight connector installed inside your network. That connector dials outbound to the Microsoft cloud, so no inbound firewall ports are required, and no public IP is exposed for the private resource.
The Global Secure Access client routes only the traffic you scope to that connector. A browser session works too, for clientless scenarios.
Capabilities worth knowing before a pilot:
- Per-app segmentation for web apps and for TCP and UDP protocols including RDP, SSH, and legacy client-server apps.
- MFA and device compliance on every connection, including on legacy apps that could never enforce that level of security natively.
- Traffic routed through the Microsoft global backbone, which often outperforms the public internet for users traveling or working from constrained networks.
One deployment note that catches teams off guard: the Windows Global Secure Access client requires the endpoint to be Entra-joined or hybrid-joined. Audit your identity posture on endpoints before you scope the pilot.
VPN vs Entra Private Access
|
Dimension |
Traditional VPN |
Entra Private Access |
|---|---|---|
|
Access model |
Broad network access after tunnel up |
Per-app, per-session, identity-gated |
|
Authentication |
Once, at connect |
Continuous, every request |
|
MFA on legacy protocols |
Rarely feasible |
Enforced through Conditional Access |
|
Firewall exposure |
Inbound ports for concentrators |
Outbound-only connectors |
|
Lateral movement risk |
High if credential is stolen |
Contained to scoped apps |
|
Policy plane |
Separate from identity and SaaS |
Unified with Conditional Access |
|
Client experience |
Full tunnel, reconnect loops |
Split tunnel, transparent client |
How Entra Internet Access Secures SaaS and AI Traffic
The other half of Global Secure Access handles outbound traffic to the internet, SaaS apps, and AI services. It is positioned as a direct replacement for standalone secure web gateways such as Zscaler or Netskope for many workloads.
At the base layer, it does what any modern SWG does: web content filtering by category, URL, and fully qualified domain name, threat intelligence blocking, and detailed traffic logs.
What sets Internet Access apart in the Entra Suite is the AI gateway layer that Microsoft added in the last cycle of updates. It provides:
- Shadow AI discovery. Network-level visibility into unsanctioned generative AI apps employees and agents are reaching.
- Unauthorized AI app blocking. Control over which generative AI tools employees are allowed to use.
- Data loss controls for prompts. Filtering for what users are permitted to upload into approved tools.
- AI prompt shielding. Protection against prompt-based attacks at the network layer.
- AI interaction logging and auditing. Evidence for compliance, investigation, or policy review.
Private Access narrows access to internal resources. Internet Access extends the same identity-aware control model to the internet, SaaS apps, and AI traffic. Because policies are attached to the user through Conditional Access, the same allow, warn, or block decision follows the person across device, network, and location.
How does Conditional Access Control Global Secure Access?
Conditional Access is the single policy engine behind both halves of Global Secure Access. That is the reason the suite feels different from bolting a SASE product onto Entra ID. Private app access, SaaS traffic, and AI usage are all governed by the same policies you already use across Microsoft 365, evaluated continuously rather than once at connect.
What does Entra Suite Cost Compared to your Current Tools?
For teams weighing Entra Suite against renewing a SASE contract, the decision usually comes down to cost. Instead of looking at Entra Suite as another add-on, compare it against the tools already in the stack.
|
Current tool category |
Common cost or complexity driver |
Entra Suite capability to compare |
|---|---|---|
|
VPN concentrators and licenses |
Hardware refresh, client licensing, patching, and internet-facing appliance risk |
Entra Private Access |
|
Standalone secure web gateway |
Separate policy console, SaaS filtering rules, zero-day vulnerabilities and per-user seat costs |
Entra Internet Access |
At $12 per user per month, the bundle comes in below what a standalone VPN and secure web gateway typically cost on their own, before you count the other tools it can displace. If your current stack is already Microsoft-heavy, Entra Suite may reduce overlap across VPN, SWG, and AI traffic controls.
How Much does Entra Suite Cost?
Global Secure Access can be licensed in a few different ways, depending on whether the customer wants the full Entra bundle or only one access component.
The main paths are:
-
Microsoft Entra Suite, listed at $12 per user per month as an add-on to a qualifying Entra ID P1 base
-
Microsoft 365 E7, listed at $99 per user per month, which includes Entra Suite as part of the broader E7 bundle
-
Entra Private Access standalone, for customers that only want the VPN replacement/ZTNA component for private apps
-
Entra Internet Access standalone, for customers that only want the secure web and AI gateway component for internet, SaaS, and AI traffic
-
Separate component purchase/deployment, where Private Access and Internet Access are licensed individually instead of adopting the full suite.
Entra ID P1 is still the required base license, so Business Premium, Microsoft 365 E3, Microsoft 365 E5, and Microsoft 365 E7 already satisfy that prerequisite, while Business Basic and Business Standard typically require a P1 add-on first.
Microsoft Entra Suite and Global Secure Access FAQ
-
What is the difference between Global Secure Access, Entra Private Access, and Entra Internet Access?
Global Secure Access is the platform, Microsoft's Security Service Edge. Entra Private Access is the component inside it that secures private apps and replaces the VPN, and Entra Internet Access is the component that secures internet, SaaS, and AI traffic like a secure web gateway.
-
Does Entra Private Access replace a VPN?
Yes, for most private app scenarios. It swaps broad network access for per-app, identity-gated access using outbound-only connectors, so a stolen credential no longer becomes a master key to the internal network. Environments without a clear inventory of internal apps should plan a discovery phase first rather than treat it as a drop-in swap.
-
Can Entra Internet Access replace Zscaler or Netskope?
For many workloads, yes. It provides identity-based web content filtering, threat blocking, and traffic logging like a standalone secure web gateway, with the added advantage of running on the same Conditional Access engine as the rest of Microsoft 365. Very high-throughput or deep-inspection environments should validate it against their current tool during a pilot.
-
Is Entra ID P1 required for Entra Suite?
Yes. Entra ID P1 is the required base and is already included in Business Premium, Microsoft 365 E3, and E5. Business Basic and Business Standard do not include P1.
-
What licenses include Microsoft Entra Suite?Microsoft 365 E7 includes Entra Suite. Every other plan treats it as a $12 per user per month add-on that requires Entra ID P1 as the base license. Business Premium, Microsoft 365 E3, and E5 already include P1. Business Basic and Business Standard do not and need a P1 add-on first.
-
What is the difference between Entra Private Access and a VPN?A VPN grants broad network access after one authentication. Entra Private Access grants access to a single application and re-evaluates identity on every request. It uses outbound-only connectors, so no inbound firewall ports are exposed, and it enforces MFA on protocols like RDP and SSH that could never enforce it natively.
Is Entra Suite the Right VPN Replacement for your Stack?
Legacy VPNs solve connectivity, but they do not solve modern access control. Microsoft Entra Suite uses Global Secure Access to narrow private app access, apply Conditional Access to internet and SaaS traffic, and add visibility into AI use.
For Microsoft 365 environments, the decision comes down to whether separate VPN, SWG, and PIM tools still justify their cost and complexity when the same controls can be managed closer to identity. If you want a second set of eyes on where Entra Suite fits your current stack, or you have questions about licensing and rollout, reach out to us and we can walk through it with you.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!
