Identity · Zero Trust · Entra Suite · 6 min read

Entra Private Access: licensed but not configured — how to tell

Published August 2026 · By M365Clarity

← All articles

If your organisation holds Microsoft 365 E7 or the standalone Entra Suite, you already have Entra Private Access. Not "eligible to buy" — already entitled to it, sitting unused, most likely. Industry coverage of the 2026 Entra Suite rollout has been consistent on this point: most organisations that have it available haven't turned it on. Licensing and configuration are two different milestones, and it's easy to tick the first one off during a renewal conversation and never come back to the second.

What it actually replaces

Entra Private Access is Microsoft's zero-trust alternative to a traditional VPN. Instead of a client establishing a tunnel into your network and then relying on network-level trust, Private Access publishes specific internal applications individually and evaluates access per-application, per-request, against the same Conditional Access policies that govern everything else in Entra. No broad network access grant, no flat "you're on the VPN so you're trusted" assumption.

It's part of what Microsoft calls Global Secure Access — the umbrella term covering both Entra Internet Access (securing outbound traffic to the internet and SaaS apps) and Entra Private Access (securing inbound access to your own private apps). They're related but distinct services, configured separately.

Why "licensed" and "configured" are different questions

Getting Private Access running isn't a licence toggle. A tenant has to explicitly onboard to Global Secure Access, then enable the private traffic forwarding profile specifically — one of three default profiles (Microsoft 365, Internet, and Private) that ship disabled by default. Onboarding without enabling the private profile is a genuinely common in-between state: technically started, not actually protecting anything yet.

1
Onboard the tenant to Global Secure Access
A one-time step in the Entra admin centre before any of the individual services can be configured.
2
Enable the Private traffic forwarding profile
Disabled by default, separately from the Internet and Microsoft 365 profiles. This is the step most tenants that have "started" Global Secure Access haven't reached.
3
Deploy a private network connector
Lightweight software that lets Entra reach your internal, on-premises or cloud-hosted applications without exposing them directly to the internet.
4
Publish specific applications
Each internal app gets published individually rather than granting broad network access — the core difference from a traditional VPN.

Why this is worth checking even if you're not actively planning a VPN replacement project: if the licence is already sitting in your tenant through E7 or the Entra Suite, the cost of turning it on has already been paid. The only thing separating "still on legacy VPN" from "zero-trust private app access" for a lot of organisations right now is nobody has gone back and finished the configuration.

What "not configured" looks like from the outside

There's no dramatic failure state here — no error, no red banner in the admin centre demanding attention. Private Access that's never been onboarded simply looks the same as a tenant that never had the licence at all. That's exactly why it's easy to miss: nothing is actively broken, so nothing prompts anyone to go and check.

Find out if Entra Private Access is actually configured

M365Clarity checks whether your tenant has onboarded to Global Secure Access and enabled the private forwarding profile — not just whether you're licensed for it.

Run a free scan →

Related articles